{
  "CVE_data_type" : "CVE",
  "CVE_data_format" : "MITRE",
  "CVE_data_version" : "4.0",
  "CVE_data_numberOfCVEs" : "7155",
  "CVE_data_timestamp" : "2020-09-15T08:49Z",
  "CVE_Items" : [ {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0001",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.49",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.55",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.56",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.57",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.58",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.59",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.15",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "2.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.13",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=974a9f0b47da74e28f68b9c8645c3786aa5ace1a",
          "name" : "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=974a9f0b47da74e28f68b9c8645c3786aa5ace1a",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.16",
          "name" : "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.16",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html",
          "name" : "SUSE-SA:2008:006",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00002.html",
          "name" : "SUSE-SA:2008:013",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2008-0055.html",
          "name" : "RHSA-2008:0055",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28485",
          "name" : "28485",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28558",
          "name" : "28558",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28626",
          "name" : "28626",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28628",
          "name" : "28628",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28643",
          "name" : "28643",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28664",
          "name" : "28664",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28706",
          "name" : "28706",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28748",
          "name" : "28748",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28806",
          "name" : "28806",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28971",
          "name" : "28971",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29245",
          "name" : "29245",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019289",
          "name" : "1019289",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0021",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0021",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1479",
          "name" : "DSA-1479",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23.14",
          "name" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23.14",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:044",
          "name" : "MDVSA-2008:044",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:112",
          "name" : "MDVSA-2008:112",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0089.html",
          "name" : "RHSA-2008:0089",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486485/100/0/threaded",
          "name" : "20080117 rPSA-2008-0021-1 kernel",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27280",
          "name" : "27280",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-574-1",
          "name" : "USN-574-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-578-1",
          "name" : "USN-578-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0151",
          "name" : "ADV-2008-0151",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39672",
          "name" : "linux-directory-security-bypass(39672)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2146",
          "name" : "https://issues.rpath.com/browse/RPL-2146",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9709",
          "name" : "oval:org.mitre.oval:def:9709",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00828.html",
          "name" : "FEDORA-2008-0748",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.31:-rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.31:-rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.31:-rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.31:-rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.31:-rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.38:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.43:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.44:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.45:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.46:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.49:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.55:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.56:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.57:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.58:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.59:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.61:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.6.22.15"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.13:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2018-10-15T21:56Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0002",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "tomcat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html",
          "name" : "APPLE-SA-2008-10-09",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html",
          "name" : "SUSE-SR:2009:004",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=139344343412337&w=2",
          "name" : "HPSBST02955",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28834",
          "name" : "28834",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28915",
          "name" : "28915",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29711",
          "name" : "29711",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32222",
          "name" : "32222",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/37460",
          "name" : "37460",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/57126",
          "name" : "57126",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200804-10.xml",
          "name" : "GLSA-200804-10",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3638",
          "name" : "3638",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT3216",
          "name" : "http://support.apple.com/kb/HT3216",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://tomcat.apache.org/security-6.html",
          "name" : "http://tomcat.apache.org/security-6.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487812/100/0/threaded",
          "name" : "20080208 CVE-2008-0002: Tomcat information disclosure vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/507985/100/0/threaded",
          "name" : "20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27703",
          "name" : "27703",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/31681",
          "name" : "31681",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/security/advisories/VMSA-2009-0016.html",
          "name" : "http://www.vmware.com/security/advisories/VMSA-2009-0016.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0488",
          "name" : "ADV-2008-0488",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2780",
          "name" : "ADV-2008-2780",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2009/3316",
          "name" : "ADV-2009-3316",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00315.html",
          "name" : "FEDORA-2008-1467",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00460.html",
          "name" : "FEDORA-2008-1603",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.15:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2018-10-15T21:56Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0003",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openpegasus",
            "product" : {
              "product_data" : [ {
                "product_name" : "management_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01438409",
          "name" : "HPSBMA02331",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://lists.vmware.com/pipermail/security-announce/2008/000014.html",
          "name" : "[Security-announce] 20080415 VMSA-2008-0007 Moderate Updated Service Console packages pcre, net-snmp, and OpenPegasus",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/40082",
          "name" : "40082",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28338",
          "name" : "28338",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28462",
          "name" : "28462",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29056",
          "name" : "29056",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29785",
          "name" : "29785",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29986",
          "name" : "29986",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019159",
          "name" : "1019159",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2008-January/001879.html",
          "name" : "20080115 vuldb confusion between OpenPegasus issues",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0002.html",
          "name" : "RHSA-2008:0002",
          "refsource" : "REDHAT",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/490917/100/0/threaded",
          "name" : "20080416 VMSA-2008-0007 Moderate Updated Service Console packages pcre, net-snmp, and OpenPegasus",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27172",
          "name" : "27172",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27188",
          "name" : "27188",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0063",
          "name" : "ADV-2008-0063",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0638",
          "name" : "ADV-2008-0638",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1234/references",
          "name" : "ADV-2008-1234",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1391/references",
          "name" : "ADV-2008-1391",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4129",
          "name" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4129",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=426578",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=426578",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39527",
          "name" : "openpegasus-pambasic-bo(39527)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10282",
          "name" : "oval:org.mitre.oval:def:10282",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00424.html",
          "name" : "FEDORA-2008-0506",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00480.html",
          "name" : "FEDORA-2008-0572",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the PAMBasicAuthenticator::PAMCallback function in OpenPegasus CIM management server (tog-pegasus), when compiled to use PAM and without PEGASUS_USE_PAM_STANDALONE_PROC defined, might allow remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2007-5360."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:4.0:*:as:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:4.0:*:es:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:4.0:*:ws:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:4.5.z:*:as:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:4.5.z:*:es:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:openpegasus:management_server:2.6.1:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T20:46Z",
    "lastModifiedDate" : "2018-10-15T21:56Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0004",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2009-03-26T10:12Z",
    "lastModifiedDate" : "2009-03-26T10:12Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0005",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html",
          "name" : "SUSE-SA:2008:021",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.vmware.com/pipermail/security-announce/2009/000062.html",
          "name" : "[security-announce] 20090820 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=124654546101607&w=2",
          "name" : "SSRT090085",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=125631037611762&w=2",
          "name" : "HPSBUX02465",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=130497311408250&w=2",
          "name" : "SSRT090208",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28467",
          "name" : "28467",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28471",
          "name" : "28471",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28526",
          "name" : "28526",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28607",
          "name" : "28607",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28749",
          "name" : "28749",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28977",
          "name" : "28977",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29348",
          "name" : "29348",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29640",
          "name" : "29640",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30732",
          "name" : "30732",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/35650",
          "name" : "35650",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-19.xml",
          "name" : "GLSA-200803-19",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/achievement_securityalert/49",
          "name" : "20080110 Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability",
          "refsource" : "SREASONRES",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3526",
          "name" : "3526",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:014",
          "name" : "MDVSA-2008:014",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:015",
          "name" : "MDVSA-2008:015",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:016",
          "name" : "MDVSA-2008:016",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0004.html",
          "name" : "RHSA-2008:0004",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0005.html",
          "name" : "RHSA-2008:0005",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0006.html",
          "name" : "RHSA-2008:0006",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0007.html",
          "name" : "RHSA-2008:0007",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0008.html",
          "name" : "RHSA-2008:0008",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0009.html",
          "name" : "RHSA-2008:0009",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486167/100/0/threaded",
          "name" : "20080110 SecurityReason - Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/505990/100/0/threaded",
          "name" : "20090821 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27234",
          "name" : "27234",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019185",
          "name" : "1019185",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-575-1",
          "name" : "USN-575-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1875/references",
          "name" : "ADV-2008-1875",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39615",
          "name" : "apache-modproxyftp-utf7-xss(39615)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20190815 svn commit: r1048743 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20190815 svn commit: r1048742 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20200401 svn commit: r1058586 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20200401 svn commit: r1058586 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20200401 svn commit: r1058587 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20200401 svn commit: r1058587 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10812",
          "name" : "oval:org.mitre.oval:def:10812",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html",
          "name" : "FEDORA-2008-1711",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html",
          "name" : "FEDORA-2008-1695",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-12T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:56Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0006",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris_libfont",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "solaris_libxfont",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "x.org",
            "product" : {
              "product_data" : [ {
                "product_name" : "xserver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=204362",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=204362",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01543321",
          "name" : "SSRT080083",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://jvn.jp/en/jp/JVN88935101/index.html",
          "name" : "JVN#88935101",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001043.html",
          "name" : "JVNDB-2008-001043",
          "refsource" : "JVNDB",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.freedesktop.org/archives/xorg/2008-January/031918.html",
          "name" : "[xorg] 20080117 X.Org security advisory: multiple vulnerabilities in the X server",
          "refsource" : "MLIST",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00004.html",
          "name" : "SUSE-SA:2008:003",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html",
          "name" : "SUSE-SR:2008:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28273",
          "name" : "28273",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28500",
          "name" : "28500",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28532",
          "name" : "28532",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28535",
          "name" : "28535",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28536",
          "name" : "28536",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28540",
          "name" : "28540",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28542",
          "name" : "28542",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28544",
          "name" : "28544",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28550",
          "name" : "28550",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28571",
          "name" : "28571",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28592",
          "name" : "28592",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28621",
          "name" : "28621",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28718",
          "name" : "28718",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28843",
          "name" : "28843",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28885",
          "name" : "28885",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28941",
          "name" : "28941",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29139",
          "name" : "29139",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29622",
          "name" : "29622",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29707",
          "name" : "29707",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30161",
          "name" : "30161",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32545",
          "name" : "32545",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200801-09.xml",
          "name" : "GLSA-200801-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200804-05.xml",
          "name" : "GLSA-200804-05",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019232",
          "name" : "1019232",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-103192-1",
          "name" : "103192",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-201230-1",
          "name" : "201230",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2008-038.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2008-038.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2008-077.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2008-077.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml",
          "name" : "GLSA-200805-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/203220",
          "name" : "VU#203220",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:021",
          "name" : "MDVSA-2008:021",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:022",
          "name" : "MDVSA-2008:022",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:024",
          "name" : "MDVSA-2008:024",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.openbsd.org/errata41.html#012_xorg",
          "name" : "[4.1] 20080208 012: SECURITY FIX: February 8, 2008",
          "refsource" : "OPENBSD",
          "tags" : [ ]
        }, {
          "url" : "http://www.openbsd.org/errata42.html#006_xorg",
          "name" : "[4.2] 20080208 006: SECURITY FIX: February 8, 2008",
          "refsource" : "OPENBSD",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0029.html",
          "name" : "RHSA-2008:0029",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0030.html",
          "name" : "RHSA-2008:0030",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0064.html",
          "name" : "RHSA-2008:0064",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487335/100/0/threaded",
          "name" : "20080130 rPSA-2008-0032-1 xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27336",
          "name" : "27336",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27352",
          "name" : "27352",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0179",
          "name" : "ADV-2008-0179",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0184",
          "name" : "ADV-2008-0184",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0497/references",
          "name" : "ADV-2008-0497",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0703",
          "name" : "ADV-2008-0703",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/3000",
          "name" : "ADV-2008-3000",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX61&path=/200802/SECURITY/20080227/datafile112539&label=AIX%20X%20server%20multiple%20vulnerabilities",
          "name" : "http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX61&path=/200802/SECURITY/20080227/datafile112539&label=AIX%20X%20server%20multiple%20vulnerabilities",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=428044",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=428044",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39767",
          "name" : "xorg-pcffont-bo(39767)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2010",
          "name" : "https://issues.rpath.com/browse/RPL-2010",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10021",
          "name" : "oval:org.mitre.oval:def:10021",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/571-1/",
          "name" : "USN-571-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00641.html",
          "name" : "FEDORA-2008-0760",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00674.html",
          "name" : "FEDORA-2008-0794",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00704.html",
          "name" : "FEDORA-2008-0831",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00771.html",
          "name" : "FEDORA-2008-0891",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:solaris_libfont:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:solaris_libxfont:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:x.org:xserver:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-18T23:00Z",
    "lastModifiedDate" : "2018-10-15T21:56Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0007",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.22.16",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html",
          "name" : "SUSE-SA:2008:006",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00007.html",
          "name" : "SUSE-SA:2008:017",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.vmware.com/pipermail/security-announce/2008/000023.html",
          "name" : "[Security-announce] 20080728 VMSA-2008-00011 Updated ESX service console packages for Samba and vmnix",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://lkml.org/lkml/2008/2/6/457",
          "name" : "[linux-kernel] 20080206 [patch 60/73] vm audit: add VM_DONTEXPAND to mmap for drivers that need it (CVE-2008-0007)",
          "refsource" : "MLIST",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28806",
          "name" : "28806",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28826",
          "name" : "28826",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29058",
          "name" : "29058",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29570",
          "name" : "29570",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30018",
          "name" : "30018",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30110",
          "name" : "30110",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30112",
          "name" : "30112",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30116",
          "name" : "30116",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30769",
          "name" : "30769",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31246",
          "name" : "31246",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/33280",
          "name" : "33280",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019357",
          "name" : "1019357",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0048",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0048",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1503",
          "name" : "DSA-1503",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1504",
          "name" : "DSA-1504",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1565",
          "name" : "DSA-1565",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.17",
          "name" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.17",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1",
          "name" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:044",
          "name" : "MDVSA-2008:044",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:072",
          "name" : "MDVSA-2008:072",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:112",
          "name" : "MDVSA-2008:112",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:174",
          "name" : "MDVSA-2008:174",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0211.html",
          "name" : "RHSA-2008:0211",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0233.html",
          "name" : "RHSA-2008:0233",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0237.html",
          "name" : "RHSA-2008:0237",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0787.html",
          "name" : "RHSA-2008:0787",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487808/100/0/threaded",
          "name" : "20080208 rPSA-2008-0048-1 kernel",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27686",
          "name" : "27686",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27705",
          "name" : "27705",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-618-1",
          "name" : "USN-618-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0445/references",
          "name" : "ADV-2008-0445",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2222/references",
          "name" : "ADV-2008-2222",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9412",
          "name" : "oval:org.mitre.oval:def:9412",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Linux kernel before 2.6.22.17, when using certain drivers that register a fault handler that does not perform range checks, allows local users to access kernel memory via an out-of-range offset."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.6.22.16"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-08T02:00Z",
    "lastModifiedDate" : "2018-10-15T21:56Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0008",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pulseaudio",
            "product" : {
              "product_data" : [ {
                "product_name" : "pulseaudio",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=207214",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=207214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://pulseaudio.org/changeset/2100",
          "name" : "http://pulseaudio.org/changeset/2100",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28608",
          "name" : "28608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28623",
          "name" : "28623",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28738",
          "name" : "28738",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28952",
          "name" : "28952",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200802-07.xml",
          "name" : "GLSA-200802-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1476",
          "name" : "DSA-1476",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:027",
          "name" : "MDVSA-2008:027",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27449",
          "name" : "27449",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-573-1",
          "name" : "USN-573-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0283",
          "name" : "ADV-2008-0283",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.novell.com/show_bug.cgi?id=347822",
          "name" : "https://bugzilla.novell.com/show_bug.cgi?id=347822",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=425481",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=425481",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39992",
          "name" : "pulseaudio-padroproot-privilege-escalation(39992)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://tango.0pointer.de/pipermail/pulseaudio-discuss/2008-January/001228.html",
          "name" : "[pulseaudio-discuss] 20080124 [ANNOUNCE] PulseAudio 0.9.9",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00852.html",
          "name" : "FEDORA-2008-0963",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00869.html",
          "name" : "FEDORA-2008-0994",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource exhaustion."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2007.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2007.1:*:x86-64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2008.0:*:x86-64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:fedora:7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:fedora:8:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:pulseaudio:pulseaudio:0.9.6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:pulseaudio:pulseaudio:0.9.8:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T00:00Z",
    "lastModifiedDate" : "2017-07-29T01:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0009",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.24",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt",
          "name" : "http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28835",
          "name" : "28835",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28896",
          "name" : "28896",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1",
          "name" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487982/100/0/threaded",
          "name" : "20080212 CSA-L03: Linux kernel vmsplice unchecked user-pointer dereference",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27704",
          "name" : "27704",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27799",
          "name" : "27799",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0487/references",
          "name" : "ADV-2008-0487",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=431206",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=431206",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00254.html",
          "name" : "FEDORA-2008-1422",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00255.html",
          "name" : "FEDORA-2008-1423",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.24:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.24:rc3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T21:00Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0010",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.24",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt",
          "name" : "http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28835",
          "name" : "28835",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28875",
          "name" : "28875",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28896",
          "name" : "28896",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1494",
          "name" : "DSA-1494",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1",
          "name" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487982/100/0/threaded",
          "name" : "20080212 CSA-L03: Linux kernel vmsplice unchecked user-pointer dereference",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27704",
          "name" : "27704",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27796",
          "name" : "27796",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0487/references",
          "name" : "ADV-2008-0487",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5093",
          "name" : "5093",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00254.html",
          "name" : "FEDORA-2008-1422",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00255.html",
          "name" : "FEDORA-2008-1423",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which allow local users to read from arbitrary kernel memory locations."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.24:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.24:rc3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T21:00Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0011",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "directx",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=121380194923597&w=2",
          "name" : "HPSBST02344",
          "refsource" : "HP",
          "tags" : [ "Mailing List" ]
        }, {
          "url" : "http://secunia.com/advisories/30579",
          "name" : "30579",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1020222",
          "name" : "1020222",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29581",
          "name" : "29581",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-162B.html",
          "name" : "TA08-162B",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1780",
          "name" : "ADV-2008-1780",
          "refsource" : "VUPEN",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-033",
          "name" : "MS08-033",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5236",
          "name" : "oval:org.mitre.oval:def:5236",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJPEG stream in a (1) AVI or (2) ASF file, aka the \"MJPEG Decoder Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:xp:sp3:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:x64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:directx:9.0:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:directx:7.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:directx:8.1:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:2008:*:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:2008:*:x32:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:2008:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:x64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:directx:10.0:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-06-12T02:32Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0012",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "trend_micro",
            "product" : {
              "product_data" : [ {
                "product_name" : "serverprotect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.58",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.iss.net/archive/trend.html",
          "name" : "http://blogs.iss.net/archive/trend.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32618",
          "name" : "32618",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.iss.net/threats/310.html",
          "name" : "20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)",
          "refsource" : "ISS",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/768681",
          "name" : "VU#768681",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/32261",
          "name" : "32261",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/3127",
          "name" : "ADV-2008-3127",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39918",
          "name" : "application-rpc-config1-bo(39918)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-2008-0013 and CVE-2008-0014."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.58:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-11-17T23:30Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0013",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "trend_micro",
            "product" : {
              "product_data" : [ {
                "product_name" : "serverprotect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.58",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.iss.net/archive/trend.html",
          "name" : "http://blogs.iss.net/archive/trend.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32618",
          "name" : "32618",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.iss.net/threats/310.html",
          "name" : "20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)",
          "refsource" : "ISS",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/768681",
          "name" : "VU#768681",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/32261",
          "name" : "32261",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/3127",
          "name" : "ADV-2008-3127",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39919",
          "name" : "application-rpc-config2-bo(39919)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-2008-0012 and CVE-2008-0014."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.58:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-11-17T23:30Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0014",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "trend_micro",
            "product" : {
              "product_data" : [ {
                "product_name" : "serverprotect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.58",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.iss.net/archive/trend.html",
          "name" : "http://blogs.iss.net/archive/trend.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32618",
          "name" : "32618",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.iss.net/threats/310.html",
          "name" : "20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)",
          "refsource" : "ISS",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/768681",
          "name" : "VU#768681",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/32261",
          "name" : "32261",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/3127",
          "name" : "ADV-2008-3127",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39920",
          "name" : "application-rpc-config3-bo(39920)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-2008-0012 and CVE-2008-0013."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.58:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-11-17T23:30Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0015",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx",
          "name" : "http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://isc.sans.org/diary.html?storyid=6733",
          "name" : "http://isc.sans.org/diary.html?storyid=6733",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/55651",
          "name" : "55651",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/36187",
          "name" : "36187",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.csis.dk/dk/nyheder/nyheder.asp?tekstID=799",
          "name" : "http://www.csis.dk/dk/nyheder/nyheder.asp?tekstID=799",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.iss.net/threats/329.html",
          "name" : "20090706 Multiple Microsoft Video Control ActiveX Remote Code Execution Vulnerabilities",
          "refsource" : "ISS",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/180513",
          "name" : "VU#180513",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.microsoft.com/technet/security/advisory/972890.mspx",
          "name" : "http://www.microsoft.com/technet/security/advisory/972890.mspx",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/35558",
          "name" : "35558",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/35585",
          "name" : "35585",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1022514",
          "name" : "1022514",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA09-187A.html",
          "name" : "TA09-187A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA09-195A.html",
          "name" : "TA09-195A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA09-223A.html",
          "name" : "TA09-223A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2009/2232",
          "name" : "ADV-2009-2232",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-032",
          "name" : "MS09-032",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-037",
          "name" : "MS09-037",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6333",
          "name" : "oval:org.mitre.oval:def:6333",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6363",
          "name" : "oval:org.mitre.oval:def:6363",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7436",
          "name" : "oval:org.mitre.oval:def:7436",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka \"Microsoft Video ActiveX Control Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:-:sp2:itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:-:sp2:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:professional_x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2009-07-07T23:30Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0016",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9_rc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.16",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.99",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://download.novell.com/Download?buildid=WZXONb-tqBw~",
          "name" : "http://download.novell.com/Download?buildid=WZXONb-tqBw~",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.html",
          "name" : "SUSE-SA:2008:050",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31984",
          "name" : "31984",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31985",
          "name" : "31985",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32010",
          "name" : "32010",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32012",
          "name" : "32012",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32042",
          "name" : "32042",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32044",
          "name" : "32044",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32082",
          "name" : "32082",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32092",
          "name" : "32092",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32144",
          "name" : "32144",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32185",
          "name" : "32185",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32196",
          "name" : "32196",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32845",
          "name" : "32845",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/33433",
          "name" : "33433",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/33434",
          "name" : "33434",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/34501",
          "name" : "34501",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.379422",
          "name" : "SSA:2008-269-02",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.405232",
          "name" : "SSA:2008-269-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.412123",
          "name" : "SSA:2008-270-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1",
          "name" : "256408",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1649",
          "name" : "DSA-1649",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1669",
          "name" : "DSA-1669",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2009/dsa-1696",
          "name" : "DSA-1696",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2009/dsa-1697",
          "name" : "DSA-1697",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:205",
          "name" : "MDVSA-2008:205",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:206",
          "name" : "MDVSA-2008:206",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-37.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-37.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0882.html",
          "name" : "RHSA-2008:0882",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0908.html",
          "name" : "RHSA-2008:0908",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/31397",
          "name" : "31397",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020913",
          "name" : "1020913",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-645-1",
          "name" : "USN-645-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-645-2",
          "name" : "USN-645-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2661",
          "name" : "ADV-2008-2661",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2009/0977",
          "name" : "ADV-2009-0977",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=443288",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=443288",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=451617",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=451617",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11579",
          "name" : "oval:org.mitre.oval:def:11579",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01384.html",
          "name" : "FEDORA-2008-8401",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01403.html",
          "name" : "FEDORA-2008-8429",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9:rc:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9_rc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.16"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:dev:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.99:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-09-24T20:37Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0017",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.html",
          "name" : "SUSE-SA:2008:055",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/32684",
          "name" : "32684",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/32693",
          "name" : "32693",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/32694",
          "name" : "32694",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/32695",
          "name" : "32695",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/32713",
          "name" : "32713",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/32714",
          "name" : "32714",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/32721",
          "name" : "32721",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/32778",
          "name" : "32778",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/32845",
          "name" : "32845",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/32853",
          "name" : "32853",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/33433",
          "name" : "33433",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/34501",
          "name" : "34501",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1",
          "name" : "256408",
          "refsource" : "SUNALERT",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://ubuntu.com/usn/usn-667-1",
          "name" : "USN-667-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1669",
          "name" : "DSA-1669",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1671",
          "name" : "DSA-1671",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2009/dsa-1697",
          "name" : "DSA-1697",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.iss.net/threats/311.html",
          "name" : "20081113 Mozilla Unchecked Allocation Remote Code Execution",
          "refsource" : "ISS",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:228",
          "name" : "MDVSA-2008:228",
          "refsource" : "MANDRIVA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:230",
          "name" : "MDVSA-2008:230",
          "refsource" : "MANDRIVA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-54.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-54.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0977.html",
          "name" : "RHSA-2008:0977",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0978.html",
          "name" : "RHSA-2008:0978",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/32281",
          "name" : "32281",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1021185",
          "name" : "1021185",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-319A.html",
          "name" : "TA08-319A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/3146",
          "name" : "ADV-2008-3146",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2009/0977",
          "name" : "ADV-2009-0977",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=443299",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=443299",
          "refsource" : "MISC",
          "tags" : [ "Issue Tracking", "Vendor Advisory" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11005",
          "name" : "oval:org.mitre.oval:def:11005",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html",
          "name" : "FEDORA-2008-9667",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html",
          "name" : "FEDORA-2008-9669",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.0",
          "versionEndExcluding" : "2.0.0.18"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "3.0",
          "versionEndExcluding" : "3.0.4"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.0",
          "versionEndExcluding" : "1.1.13"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-11-13T11:30Z",
    "lastModifiedDate" : "2018-10-26T14:19Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0020",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx",
          "name" : "http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/36187",
          "name" : "36187",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.iss.net/threats/329.html",
          "name" : "20090706 Multiple Microsoft Video Control ActiveX Remote Code Execution Vulnerabilities",
          "refsource" : "ISS",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1022712",
          "name" : "1022712",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA09-223A.html",
          "name" : "TA09-223A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2009/2232",
          "name" : "ADV-2009-2232",
          "refsource" : "VUPEN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-037",
          "name" : "MS09-037",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5850",
          "name" : "oval:org.mitre.oval:def:5850",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Load method in the IPersistStreamInit interface in the Active Template Library (ATL), as used in the Microsoft Video ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption, aka \"ATL Header Memcopy Vulnerability,\" a different vulnerability than CVE-2008-0015."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:-:sp2:itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:-:sp2:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:professional_x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2009-07-07T23:30Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0026",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "unified_callmanager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0(3a)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0(4)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0_4a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unified_communications_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0_1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0_3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0_3a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0_4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0_4a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0_4a_su1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0_1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28932",
          "name" : "28932",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7c.shtml",
          "name" : "20080213 SQL injection in Cisco Unified Communications Manager",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27775",
          "name" : "27775",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019404",
          "name" : "1019404",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0542",
          "name" : "ADV-2008-0542",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40484",
          "name" : "cucm-interface-sql-injection(40484)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_callmanager:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_callmanager:5.0\\(1\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_callmanager:5.0\\(2\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_callmanager:5.0\\(3\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_callmanager:5.0\\(3a\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_callmanager:5.0\\(4\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_callmanager:5.0_4a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_callmanager:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_callmanager:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_communications_manager:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_communications_manager:5.0_1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_communications_manager:5.0_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_communications_manager:5.0_3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_communications_manager:5.0_3a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_communications_manager:5.0_4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_communications_manager:5.0_4a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_communications_manager:5.0_4a_su1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_communications_manager:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_communications_manager:6.0_1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_communications_manager:6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-14T12:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0027",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "unified_callmanager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1(3)sr4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1(3)sr5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1(3)sr5b",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unified_communications_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.3sr2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.3sr2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dvlabs.tippingpoint.com/advisory/TPTI-08-02",
          "name" : "http://dvlabs.tippingpoint.com/advisory/TPTI-08-02",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28530",
          "name" : "28530",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3551",
          "name" : "3551",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a0080932c61.shtml",
          "name" : "20080116 Cisco Unified Communications Manager CTL Provider Heap Overflow",
          "refsource" : "CISCO",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486432/100/0/threaded",
          "name" : "20080116 TPTI-08-02: Cisco Call Manager CTLProvider Heap Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27313",
          "name" : "27313",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019223",
          "name" : "1019223",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0171",
          "name" : "ADV-2008-0171",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39704",
          "name" : "cisco-cucm-ctl-bo(39704)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attackers to cause a denial of service or execute arbitrary code via a long request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_callmanager:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_callmanager:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_callmanager:4.1\\(3\\)sr4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_callmanager:4.1\\(3\\)sr5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_callmanager:4.1\\(3\\)sr5b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_communications_manager:4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_communications_manager:4.2.3sr2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_communications_manager:4.2.3sr2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_communications_manager:4.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T03:00Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0028",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "adaptive_security_appliance_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0(0)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0(4)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0(5)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0(5.2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0(6)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0(6.7)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0(7)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0(8)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1(2.5)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1(2.27)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1(2.48)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1(2.49)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1(5)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.49",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.72",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.81",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(1.22)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(2.5)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(2.7)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(2.8)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(2.10)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(2.14)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(2.15)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(2.16)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(2.17)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(2.18)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(2.19)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(2.48)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0(3)",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "pix_firewall_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1(6)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1(6b)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2(5)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4(4)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4(7.202)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4(8)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1(4)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1(4.206)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(3.210)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(4)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(5)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(6)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(7)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(8)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(9)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3(1.200)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0(4)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0(4.101)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1(4)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1(5)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5(104)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2(3.100)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3(3.102)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3(3.109)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3(5)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0(3)",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28625",
          "name" : "28625",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20080123-asa.shtml",
          "name" : "20080123 Cisco PIX and ASA Time-to-Live Vulnerability",
          "refsource" : "CISCO",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27418",
          "name" : "27418",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019262",
          "name" : "1019262",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019263",
          "name" : "1019263",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0259",
          "name" : "ADV-2008-0259",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39862",
          "name" : "pix-asa-ttl-dos(39862)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Cisco PIX 500 Series Security Appliance and 5500 Series Adaptive Security Appliance (ASA) before 7.2(3)6 and 8.0(3), when the Time-to-Live (TTL) decrement feature is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted IP packet."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*",
            "versionEndExcluding" : "7.2\\(3\\)6"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:adaptive_security_appliance_software:8.0\\(3\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:*:*:*:*:*:*:*:*",
            "versionEndExcluding" : "7.2\\(3\\)6"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:8.0\\(3\\):*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:5500_series_adaptive_security_appliance:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:pix_500:-:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T21:00Z",
    "lastModifiedDate" : "2018-10-26T14:19Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0029",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_velocity_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-255"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20080123-avs.shtml",
          "name" : "20080123 Default Passwords in the Application Velocity System",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27421",
          "name" : "27421",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019259",
          "name" : "1019259",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0260",
          "name" : "ADV-2008-0260",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39860",
          "name" : "ciscoavs-default-password-admin-account(39860)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco Application Velocity System (AVS) before 5.1.0 is installed with default passwords for some system accounts, which allows remote attackers to gain privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:application_velocity_system_3110:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:application_velocity_system_3120:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:application_velocity_system_3180:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:application_velocity_system_3180a:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:application_velocity_system:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "5.0.1"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T21:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0030",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2008. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0031",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307301",
          "name" : "http://docs.info.apple.com/article.html?artnum=307301",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html",
          "name" : "APPLE-SA-2008-01-15",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28502",
          "name" : "28502",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27298",
          "name" : "27298",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019221",
          "name" : "1019221",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-016A.html",
          "name" : "TA08-016A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0148",
          "name" : "ADV-2008-0148",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39695",
          "name" : "quicktime-sorenson-code-execution(39695)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Sorenson 3 video file, which triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-16T02:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0032",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307301",
          "name" : "http://docs.info.apple.com/article.html?artnum=307301",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=642",
          "name" : "20080115 Apple QuickTime Macintosh Resource Processing Heap Corruption Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html",
          "name" : "APPLE-SA-2008-01-15",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28502",
          "name" : "28502",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27301",
          "name" : "27301",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019221",
          "name" : "1019221",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-016A.html",
          "name" : "TA08-016A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0148",
          "name" : "ADV-2008-0148",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39696",
          "name" : "quicktime-macintosh-code-execution(39696)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a movie file containing a Macintosh Resource record with a modified length value in the resource header, which triggers heap corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-16T03:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0033",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.3.1.70",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307301",
          "name" : "http://docs.info.apple.com/article.html?artnum=307301",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://dvlabs.tippingpoint.com/advisory/TPTI-08-01",
          "name" : "http://dvlabs.tippingpoint.com/advisory/TPTI-08-01",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html",
          "name" : "APPLE-SA-2008-01-15",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28502",
          "name" : "28502",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486413/100/0/threaded",
          "name" : "20080115 TPTI-08-01: Apple Quicktime Image File IDSC Atom Memory Corruption Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27299",
          "name" : "27299",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019221",
          "name" : "1019221",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-016A.html",
          "name" : "TA08-016A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0148",
          "name" : "ADV-2008-0148",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39697",
          "name" : "quicktime-idsc-code-execution(39697)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a movie file with Image Descriptor (IDSC) atoms containing an invalid atom size, which triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.3.1.70"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-16T03:00Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0034",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "iphone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307302",
          "name" : "http://docs.info.apple.com/article.html?artnum=307302",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Jan/msg00000.html",
          "name" : "APPLE-SA-2008-01-15",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28497",
          "name" : "28497",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27297",
          "name" : "27297",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019219",
          "name" : "1019219",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0147",
          "name" : "ADV-2008-0147",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39701",
          "name" : "iphone-passcode-lock-security-bypass(39701)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Passcode Lock in Apple iPhone 1.0 through 1.1.2 allows users with physical access to execute applications without entering the passcode via vectors related to emergency calls."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:apple:iphone:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:apple:iphone:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:apple:iphone:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:apple:iphone:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:apple:iphone:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:apple:iphone:1.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T02:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0035",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307302",
          "name" : "http://docs.info.apple.com/article.html?artnum=307302",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=307430",
          "name" : "http://docs.info.apple.com/article.html?artnum=307430",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html",
          "name" : "APPLE-SA-2008-02-11",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Jan/msg00000.html",
          "name" : "APPLE-SA-2008-01-15",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28497",
          "name" : "28497",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28891",
          "name" : "28891",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27296",
          "name" : "27296",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019220",
          "name" : "1019220",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043B.html",
          "name" : "TA08-043B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0147",
          "name" : "ADV-2008-0147",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0495/references",
          "name" : "ADV-2008-0495",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39700",
          "name" : "iphone-ipod-foundation-code-execution(39700)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Foundation, as used in Apple iPhone 1.0 through 1.1.2, iPod touch 1.1 through 1.1.2, and Mac OS X 10.5 through 10.5.1, allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted URL that triggers memory corruption in Safari."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:apple:iphone:1.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:apple:iphone:1.0.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:apple:iphone:1.0.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:apple:iphone:1.1.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:apple:iphone:1.1.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:apple:iphone:1.02:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:apple:ipod_touch:1.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:apple:ipod_touch:1.1.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:apple:ipod_touch:1.1.2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-16T02:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0036",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307301",
          "name" : "http://docs.info.apple.com/article.html?artnum=307301",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008//Jul/msg00000.html",
          "name" : "APPLE-SA-2008-07-10",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html",
          "name" : "APPLE-SA-2008-01-15",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28502",
          "name" : "28502",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31034",
          "name" : "31034",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27300",
          "name" : "27300",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019221",
          "name" : "1019221",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-016A.html",
          "name" : "TA08-016A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0148",
          "name" : "ADV-2008-0148",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2064/references",
          "name" : "ADV-2008-2064",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39698",
          "name" : "quicktime-pict-bo(39698)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a crafted compressed PICT image, which triggers the overflow during decoding."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-16T03:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0037",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307430",
          "name" : "http://docs.info.apple.com/article.html?artnum=307430",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html",
          "name" : "APPLE-SA-2008-02-11",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28891",
          "name" : "28891",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27736",
          "name" : "27736",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019365",
          "name" : "1019365",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043B.html",
          "name" : "TA08-043B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0495/references",
          "name" : "ADV-2008-0495",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "X11 in Apple Mac OS X 10.5 through 10.5.1 does not properly handle when the \"Allow connections from network client\" preference is disabled, which allows remote attackers to bypass intended access restrictions and connect to the X server."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T20:00Z",
    "lastModifiedDate" : "2011-03-08T03:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0038",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307430",
          "name" : "http://docs.info.apple.com/article.html?artnum=307430",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html",
          "name" : "APPLE-SA-2008-02-11",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28891",
          "name" : "28891",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27736",
          "name" : "27736",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019360",
          "name" : "1019360",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043B.html",
          "name" : "TA08-043B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0495/references",
          "name" : "ADV-2008-0495",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Launch Services in Apple Mac OS X 10.5 through 10.5.1 allows an uninstalled application to be launched if it is in a Time Machine backup, which might allow local users to bypass intended security restrictions or exploit vulnerabilities in the application."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T20:00Z",
    "lastModifiedDate" : "2011-03-08T03:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0039",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307430",
          "name" : "http://docs.info.apple.com/article.html?artnum=307430",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html",
          "name" : "APPLE-SA-2008-02-11",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28891",
          "name" : "28891",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27736",
          "name" : "27736",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019361",
          "name" : "1019361",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043B.html",
          "name" : "TA08-043B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0495/references",
          "name" : "ADV-2008-0495",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Mail in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary commands via a crafted file:// URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:mail:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T20:00Z",
    "lastModifiedDate" : "2011-03-08T03:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0040",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307430",
          "name" : "http://docs.info.apple.com/article.html?artnum=307430",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html",
          "name" : "APPLE-SA-2008-02-11",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28891",
          "name" : "28891",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27736",
          "name" : "27736",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019362",
          "name" : "1019362",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043B.html",
          "name" : "TA08-043B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0495/references",
          "name" : "ADV-2008-0495",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in NFS in Apple Mac OS X 10.5 through 10.5.1 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via unknown vectors related to mbuf chains that trigger memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T20:00Z",
    "lastModifiedDate" : "2011-03-08T03:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0041",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307430",
          "name" : "http://docs.info.apple.com/article.html?artnum=307430",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html",
          "name" : "APPLE-SA-2008-02-11",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28891",
          "name" : "28891",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27736",
          "name" : "27736",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019363",
          "name" : "1019363",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043B.html",
          "name" : "TA08-043B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0495/references",
          "name" : "ADV-2008-0495",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com \"when a website is unblocked,\" which allows remote attackers to determine when a system is running Parental Controls."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T20:00Z",
    "lastModifiedDate" : "2011-03-08T03:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0042",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307430",
          "name" : "http://docs.info.apple.com/article.html?artnum=307430",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html",
          "name" : "APPLE-SA-2008-02-11",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28891",
          "name" : "28891",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/774345",
          "name" : "VU#774345",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27736",
          "name" : "27736",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019364",
          "name" : "1019364",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043B.html",
          "name" : "TA08-043B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0495/references",
          "name" : "ADV-2008-0495",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Argument injection vulnerability in Terminal.app in Terminal in Apple Mac OS X 10.4.11 and 10.5 through 10.5.1 allows remote attackers to execute arbitrary code via unspecified URL schemes."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T20:00Z",
    "lastModifiedDate" : "2011-03-08T03:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0043",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "iphoto",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307398",
          "name" : "http://docs.info.apple.com/article.html?artnum=307398",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Feb/msg00000.html",
          "name" : "APPLE-SA-2008-02-05",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28805",
          "name" : "28805",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27636",
          "name" : "27636",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019307",
          "name" : "1019307",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0428/references",
          "name" : "ADV-2008-0428",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in Apple iPhoto before 7.1.2 allows remote attackers to execute arbitrary code via photocast subscriptions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:iphoto:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-08T02:00Z",
    "lastModifiedDate" : "2011-03-08T03:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0044",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28320",
          "name" : "28320",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019640",
          "name" : "1019640",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41319",
          "name" : "macos-afpclient-bo(41319)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in AFP Client in Apple Mac OS X 10.4.11 and 10.5.2 allow remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted afp:// URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-18T22:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0045",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28323",
          "name" : "28323",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019642",
          "name" : "1019642",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41318",
          "name" : "macos-afpserver-security-bypass(41318)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in AFP Server in Apple Mac OS X 10.4.11 allows remote attackers to bypass cross-realm authentication via unknown manipulations of Kerberos principal realm names."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T22:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0046",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28368",
          "name" : "28368",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019658",
          "name" : "1019658",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41317",
          "name" : "macos-applicationfirewall-weak-security(41317)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the \"Set access for specific services and applications\" radio button that might cause the user to believe that the button is used to restrict access only to specific services and applications, which might allow attackers to bypass intended access restrictions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T22:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0047",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cups",
            "product" : {
              "product_data" : [ {
                "product_name" : "cups",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=674",
          "name" : "20080318 Multiple Vendor CUPS CGI Heap Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00005.html",
          "name" : "SUSE-SA:2008:015",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29431",
          "name" : "29431",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29448",
          "name" : "29448",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29485",
          "name" : "29485",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29573",
          "name" : "29573",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29603",
          "name" : "29603",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29634",
          "name" : "29634",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29655",
          "name" : "29655",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29750",
          "name" : "29750",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200804-01.xml",
          "name" : "GLSA-200804-01",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1530",
          "name" : "DSA-1530",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:081",
          "name" : "MDVSA-2008:081",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0192.html",
          "name" : "RHSA-2008:0192",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28307",
          "name" : "28307",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019646",
          "name" : "1019646",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-598-1",
          "name" : "USN-598-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0921/references",
          "name" : "ADV-2008-0921",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10085",
          "name" : "oval:org.mitre.oval:def:10085",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00091.html",
          "name" : "FEDORA-2008-2131",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00105.html",
          "name" : "FEDORA-2008-2897",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enabled, allows remote attackers to execute arbitrary code via crafted search expressions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cups:cups:1.3.5:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0048",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28388",
          "name" : "28388",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019647",
          "name" : "1019647",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41315",
          "name" : "macos-appkit-nsdocument-bo(41315)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via the a long file name to the NSDocument API."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T22:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0049",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28340",
          "name" : "28340",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019647",
          "name" : "1019647",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41314",
          "name" : "macos-appkit-code-execution(41314)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "AppKit in Apple Mac OS X 10.4.11 inadvertently makes an NSApplication mach port available for inter-process communication instead of inter-thread communication, which allows local users to execute arbitrary code via crafted messages to privileged applications."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T22:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0050",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=307563",
          "name" : "http://docs.info.apple.com/article.html?artnum=307563",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html",
          "name" : "APPLE-SA-2008-07-11",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31074",
          "name" : "31074",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28290",
          "name" : "28290",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28356",
          "name" : "28356",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019655",
          "name" : "1019655",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0920/references",
          "name" : "ADV-2008-0920",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2094/references",
          "name" : "ADV-2008-2094",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41313",
          "name" : "macos-cfnetwork-502badgateway-spoofing(41313)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CFNetwork in Apple Mac OS X 10.4.11 allows remote HTTPS proxy servers to spoof secure websites via data in a 502 Bad Gateway error."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T22:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0051",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28375",
          "name" : "28375",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019670",
          "name" : "1019670",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41310",
          "name" : "macos-corefoundation-timezone-code-execution(41310)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in CoreFoundation in Apple Mac OS X 10.4.11 might allow local users to execute arbitrary code via crafted time zone data."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T22:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0052",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28384",
          "name" : "28384",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019671",
          "name" : "1019671",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41312",
          "name" : "macos-coreservices-weak-security(41312)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file in AppleWorks, even when the \"Open 'Safe' files\" preference is set."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0053",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "cups",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.5-1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.5-2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.6-1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.6-2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.6-3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.9-1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.10-1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.5",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00003.html",
          "name" : "SUSE-SA:2008:020",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29573",
          "name" : "29573",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29603",
          "name" : "29603",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29630",
          "name" : "29630",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29634",
          "name" : "29634",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29655",
          "name" : "29655",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29659",
          "name" : "29659",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29750",
          "name" : "29750",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31324",
          "name" : "31324",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200804-01.xml",
          "name" : "GLSA-200804-01",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1625",
          "name" : "DSA-1625",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:081",
          "name" : "MDVSA-2008:081",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0192.html",
          "name" : "RHSA-2008:0192",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0206.html",
          "name" : "RHSA-2008:0206",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28334",
          "name" : "28334",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019672",
          "name" : "1019672",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-598-1",
          "name" : "USN-598-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41272",
          "name" : "macos-cups-inputvalidation-unspecified(41272)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10356",
          "name" : "oval:org.mitre.oval:def:10356",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00105.html",
          "name" : "FEDORA-2008-2897",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in the HP-GL/2-to-PostScript filter in CUPS before 1.3.6 might allow remote attackers to execute arbitrary code via a crafted HP-GL/2 file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.5-1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.5-2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.6-1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.6-2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.6-3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.9-1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.10-1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.19:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.19:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.19:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.19:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.19:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.20:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.20:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.20:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.20:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.20:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.20:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.21:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.21:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.22:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.22:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.1.23:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2:b1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2:b2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.2.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.3:b1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.3:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.3:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:cups:1.4.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0054",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28341",
          "name" : "28341",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019649",
          "name" : "1019649",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41355",
          "name" : "macos-nsselectorfromstring-code-execution(41355)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an \"unexpected selector\" to be used."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0055",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-362"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28343",
          "name" : "28343",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019649",
          "name" : "1019649",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41299",
          "name" : "macos-nsfilemanager-priv-escalation(41299)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permissions afterward, which allows local users to modify copied files to cause a denial of service and possibly gain privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0056",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28357",
          "name" : "28357",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019649",
          "name" : "1019649",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41309",
          "name" : "macos-foundation-nsfilemanager-bo(41309)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Foundation in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a \"long pathname with an unexpected structure\" that triggers the overflow in NSFileManager."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0057",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28358",
          "name" : "28358",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019648",
          "name" : "1019648",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41298",
          "name" : "macos-appkit-parser-bo(41298)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple integer overflows in a \"legacy serialization format\" parser in AppKit in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via a crafted serialized property list."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-18T22:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0058",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-362"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28359",
          "name" : "28359",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019650",
          "name" : "1019650",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41297",
          "name" : "macos-foundation-nsurl-code-execution(41297)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via unspecified manipulations that cause messages to be sent to a deallocated object."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0059",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-362"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28367",
          "name" : "28367",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019650",
          "name" : "1019650",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41296",
          "name" : "macos-foundation-code-execution(41296)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to \"error handling logic.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0060",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28371",
          "name" : "28371",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019657",
          "name" : "1019657",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41295",
          "name" : "macos-helpviewer-code-execution(41295)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML or JavaScript into a topic list page, as demonstrated using a help:runscript link."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0061",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "maradns",
            "product" : {
              "product_data" : [ {
                "product_name" : "maradns",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.07",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.08",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.09",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.12.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.12.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.12.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.12.05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.12.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.12.07",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.07",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.07.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.07.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.07.03",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=204351",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=204351",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://maradns.blogspot.com/2007/08/maradns-update-all-versions.html",
          "name" : "http://maradns.blogspot.com/2007/08/maradns-update-all-versions.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28329",
          "name" : "28329",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28334",
          "name" : "28334",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28650",
          "name" : "28650",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200801-16.xml",
          "name" : "GLSA-200801-16",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1445",
          "name" : "DSA-1445",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.maradns.org/changelog.html",
          "name" : "http://www.maradns.org/changelog.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27124",
          "name" : "27124",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0026",
          "name" : "ADV-2008-0026",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "MaraDNS 1.0 before 1.0.41, 1.2 before 1.2.12.08, and 1.3 before 1.3.07.04 allows remote attackers to cause a denial of service via a crafted DNS packet that prevents an authoritative name (CNAME) record from resolving, aka \"improper rotation of resource records.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.05:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.06:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.07:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.08:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.09:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.38:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.0.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.2.12.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.2.12.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.2.12.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.2.12.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.2.12.05:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.2.12.06:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.2.12.07:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.3.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.3.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.3.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.3.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.3.05:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.3.06:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.3.07:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.3.07.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.3.07.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maradns:maradns:1.3.07.03:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-03T22:46Z",
    "lastModifiedDate" : "2011-03-08T03:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0062",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mit",
            "product" : {
              "product_data" : [ {
                "product_name" : "kerberos_5",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.3_kdc",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.html",
          "name" : "SUSE-SA:2008:016",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=130497213107107&w=2",
          "name" : "SSRT100495",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29423",
          "name" : "29423",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29424",
          "name" : "29424",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29428",
          "name" : "29428",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29435",
          "name" : "29435",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29438",
          "name" : "29438",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29450",
          "name" : "29450",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29451",
          "name" : "29451",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29457",
          "name" : "29457",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29462",
          "name" : "29462",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29464",
          "name" : "29464",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29516",
          "name" : "29516",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29663",
          "name" : "29663",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30535",
          "name" : "30535",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html",
          "name" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html",
          "name" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt",
          "name" : "http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0112",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0112",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1524",
          "name" : "DSA-1524",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200803-31.xml",
          "name" : "GLSA-200803-31",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/895609",
          "name" : "VU#895609",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:069",
          "name" : "MDVSA-2008:069",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:070",
          "name" : "MDVSA-2008:070",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:071",
          "name" : "MDVSA-2008:071",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0164.html",
          "name" : "RHSA-2008:0164",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0180.html",
          "name" : "RHSA-2008:0180",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0181.html",
          "name" : "RHSA-2008:0181",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0182.html",
          "name" : "RHSA-2008:0182",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489761",
          "name" : "20080318 MITKRB5-SA-2008-001: double-free, uninitialized data vulnerabilities in krb5kdc",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489883/100/0/threaded",
          "name" : "20080319 rPSA-2008-0112-1 krb5 krb5-server krb5-services krb5-test krb5-workstation",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/493080/100/0/threaded",
          "name" : "20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28303",
          "name" : "28303",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019626",
          "name" : "1019626",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-587-1",
          "name" : "USN-587-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/security/advisories/VMSA-2008-0009.html",
          "name" : "http://www.vmware.com/security/advisories/VMSA-2008-0009.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0922/references",
          "name" : "ADV-2008-0922",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1102/references",
          "name" : "ADV-2008-1102",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1744",
          "name" : "ADV-2008-1744",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41275",
          "name" : "krb5-kdc-code-execution(41275)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9496",
          "name" : "oval:org.mitre.oval:def:9496",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html",
          "name" : "FEDORA-2008-2637",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html",
          "name" : "FEDORA-2008-2647",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "1.6.3_kdc"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-19T10:44Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0063",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mit",
            "product" : {
              "product_data" : [ {
                "product_name" : "kerberos_5",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.3_kdc",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.html",
          "name" : "SUSE-SA:2008:016",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29423",
          "name" : "29423",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29424",
          "name" : "29424",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29428",
          "name" : "29428",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29435",
          "name" : "29435",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29438",
          "name" : "29438",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29450",
          "name" : "29450",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29451",
          "name" : "29451",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29457",
          "name" : "29457",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29462",
          "name" : "29462",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29464",
          "name" : "29464",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29516",
          "name" : "29516",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29663",
          "name" : "29663",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30535",
          "name" : "30535",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html",
          "name" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html",
          "name" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt",
          "name" : "http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0112",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0112",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1524",
          "name" : "DSA-1524",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200803-31.xml",
          "name" : "GLSA-200803-31",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:069",
          "name" : "MDVSA-2008:069",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:070",
          "name" : "MDVSA-2008:070",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:071",
          "name" : "MDVSA-2008:071",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0164.html",
          "name" : "RHSA-2008:0164",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0180.html",
          "name" : "RHSA-2008:0180",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0181.html",
          "name" : "RHSA-2008:0181",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0182.html",
          "name" : "RHSA-2008:0182",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489761",
          "name" : "20080318 MITKRB5-SA-2008-001: double-free, uninitialized data vulnerabilities in krb5kdc",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489883/100/0/threaded",
          "name" : "20080319 rPSA-2008-0112-1 krb5 krb5-server krb5-services krb5-test krb5-workstation",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/493080/100/0/threaded",
          "name" : "20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28303",
          "name" : "28303",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019627",
          "name" : "1019627",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-587-1",
          "name" : "USN-587-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/security/advisories/VMSA-2008-0009.html",
          "name" : "http://www.vmware.com/security/advisories/VMSA-2008-0009.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0922/references",
          "name" : "ADV-2008-0922",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1102/references",
          "name" : "ADV-2008-1102",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1744",
          "name" : "ADV-2008-1744",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41277",
          "name" : "krb5-kdc-kerberos4-info-disclosure(41277)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8916",
          "name" : "oval:org.mitre.oval:def:8916",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html",
          "name" : "FEDORA-2008-2637",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html",
          "name" : "FEDORA-2008-2647",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka \"Uninitialized stack values.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "1.6.3_kdc"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-19T10:44Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0064",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pierreegougelet",
            "product" : {
              "product_data" : [ {
                "product_name" : "gfl_sdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.870",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "nconvert",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.85",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "xnview",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.91",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.92",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28326",
          "name" : "28326",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28710",
          "name" : "28710",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2008-1/advisory",
          "name" : "http://secunia.com/secunia_research/2008-1/advisory",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27514",
          "name" : "27514",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0328",
          "name" : "ADV-2008-0328",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0329",
          "name" : "ADV-2008-0329",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Pierre-emmanuel Gougelet (1) XnView 1.91 and 1.92, (2) NConvert 4.85, and (3) libgfl280.dll in GFL SDK 2.870 for Windows allows user-assisted remote attackers to execute arbitrary code via a crafted Radiance RGBE (.hdr) file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pierreegougelet:gfl_sdk:2.870:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pierreegougelet:nconvert:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.85"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pierreegougelet:xnview:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.91"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pierreegougelet:xnview:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.92"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2011-03-08T03:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0065",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "winamp",
            "product" : {
              "product_data" : [ {
                "product_name" : "nullsoft_winamp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.51",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/27865",
          "name" : "27865",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2008-2/advisory/",
          "name" : "http://secunia.com/secunia_research/2008-2/advisory/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27344",
          "name" : "27344",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0183",
          "name" : "ADV-2008-0183",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.winamp.com/player/version-history",
          "name" : "http://www.winamp.com/player/version-history",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39778",
          "name" : "winamp-inmp3-bo(39778)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:winamp:nullsoft_winamp:5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:winamp:nullsoft_winamp:5.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:winamp:nullsoft_winamp:5.51:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0066",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "autonomy",
            "product" : {
              "product_data" : [ {
                "product_name" : "keyview",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_notes",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28140",
          "name" : "28140",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28209",
          "name" : "28209",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28210",
          "name" : "28210",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2008-3/advisory/",
          "name" : "http://secunia.com/secunia_research/2008-3/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/490828/100/0/threaded",
          "name" : "20080414 Secunia Research: Lotus Notes htmsr.dll Buffer Overflows",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28454",
          "name" : "28454",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019843",
          "name" : "1019843",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1153",
          "name" : "ADV-2008-1153",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1156",
          "name" : "ADV-2008-1156",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21298453",
          "name" : "http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21298453",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41724",
          "name" : "autonomy-keyview-html-multiple-bo(41724)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in htmsr.dll in the HTML speed reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allow remote attackers to execute arbitrary code via an HTML document with (1) \"large chunks of data,\" or a long URL in the (2) BACKGROUND attribute of a BODY element or (3) SRC attribute of an IMG element."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:autonomy:keyview:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:7.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-10T18:05Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0067",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "openview_network_node_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.51",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=123247393715913&w=2",
          "name" : "HPSBMA02400",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28074",
          "name" : "28074",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2008-13/",
          "name" : "http://secunia.com/secunia_research/2008-13/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/4885",
          "name" : "4885",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/8307",
          "name" : "8307",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1021521",
          "name" : "1021521",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/499826/100/0/threaded",
          "name" : "20090107 Secunia Research: HP OpenView Network Node Manager Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/33147",
          "name" : "33147",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) long string parameters to the OpenView5.exe CGI program; (2) a long string parameter to the OpenView5.exe CGI program, related to ov.dll; or a long string parameter to the (3) getcvdata.exe, (4) ovlaunch.exe, or (5) Toolbar.exe CGI program."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.51:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2009-01-08T19:30Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0068",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "openview_network_node_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.53",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/closedviewx-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/closedviewx-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=121553649611253&w=2",
          "name" : "SSRT080043",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29796",
          "name" : "29796",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/secunia_research/2008-4/advisory/",
          "name" : "http://secunia.com/secunia_research/2008-4/advisory/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3814",
          "name" : "3814",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/44359",
          "name" : "44359",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/490771",
          "name" : "20080411 Directory traversal and multiple Denials of Service in HP OpenView NNM 7.53",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/490834/100/0/threaded",
          "name" : "20080414 Secunia Research: HP OpenView Network Node Manager OpenView5.exeDirectory Traversal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28745",
          "name" : "28745",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019838",
          "name" : "1019838",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019839",
          "name" : "1019839",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1214/references",
          "name" : "ADV-2008-1214",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41790",
          "name" : "hpopenview-openview5-directory-traversal(41790)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in OpenView5.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to read arbitrary files via directory traversal sequences in the Action parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.53:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-16T18:05Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0069",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pierreegougelet",
            "product" : {
              "product_data" : [ {
                "product_name" : "xnview",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.92",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.92.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29620",
          "name" : "29620",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2008-6/advisory/",
          "name" : "http://secunia.com/secunia_research/2008-6/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28579",
          "name" : "28579",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1044/references",
          "name" : "ADV-2008-1044",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41542",
          "name" : "xnview-slideshow-bo(41542)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5346",
          "name" : "5346",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long FontName parameter in a slideshow (.sld) file, a different vector than CVE-2008-1461."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pierreegougelet:xnview:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.92"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pierreegougelet:xnview:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.92.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-02T17:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0070",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "orb_networks",
            "product" : {
              "product_data" : [ {
                "product_name" : "orb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.1014",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28203",
          "name" : "28203",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2008-5/advisory/",
          "name" : "http://secunia.com/secunia_research/2008-5/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28431",
          "name" : "28431",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0984/references",
          "name" : "ADV-2008-0984",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41410",
          "name" : "orb-dimensions-bo(41410)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in Orb Networks Orb 2.00.1014 and Winamp Remote BETA allows remote attackers to execute arbitrary code via an RPC request that specifies a large number of array dimensions, which triggers a heap-based buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:orb_networks:orb:2.0.1014:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-31T17:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0071",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bittorrent",
            "product" : {
              "product_data" : [ {
                "product_name" : "bittorrent",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.9.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.9.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.9.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.9.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.20.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.20.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.20.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.20.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.20.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.20.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.20.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.20.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.22.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.22.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.22.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.24.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.24.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.26.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.27.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.27.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "utorrent",
            "product" : {
              "product_data" : [ {
                "product_name" : "utorrent",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28703",
          "name" : "28703",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30605",
          "name" : "30605",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2008-7/advisory/",
          "name" : "http://secunia.com/secunia_research/2008-7/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3943",
          "name" : "3943",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1020266",
          "name" : "1020266",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/493269/100/0/threaded",
          "name" : "20080611 Secunia Research: uTorrent / BitTorrent Web UI HTTP \"Range\" Header DoS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29661",
          "name" : "29661",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020265",
          "name" : "1020265",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1808",
          "name" : "ADV-2008-1808",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1809",
          "name" : "ADV-2008-1809",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5918",
          "name" : "5918",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a malformed Range header."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:3.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.9.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.9.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.9.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.9.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.9.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.20.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.20.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.20.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.20.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.20.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.20.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.20.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.20.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.22.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.22.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.22.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.24.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.24.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.26.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.27.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:4.27.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:5.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:5.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.0.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.7.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.7.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-06-16T18:41Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0072",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnome",
            "product" : {
              "product_data" : [ {
                "product_name" : "evolution",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.12.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00003.html",
          "name" : "SUSE-SA:2008:014",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29057",
          "name" : "29057",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29163",
          "name" : "29163",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29210",
          "name" : "29210",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29244",
          "name" : "29244",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29258",
          "name" : "29258",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29264",
          "name" : "29264",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29317",
          "name" : "29317",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30437",
          "name" : "30437",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30491",
          "name" : "30491",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2008-8/advisory/",
          "name" : "http://secunia.com/secunia_research/2008-8/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-12.xml",
          "name" : "GLSA-200803-12",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0105",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0105",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1512",
          "name" : "DSA-1512",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/512491",
          "name" : "VU#512491",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:063",
          "name" : "MDVSA-2008:063",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0177.html",
          "name" : "RHSA-2008:0177",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0178.html",
          "name" : "RHSA-2008:0178",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/492684/100/0/threaded",
          "name" : "20080528 rPSA-2008-0105-1 evolution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28102",
          "name" : "28102",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019540",
          "name" : "1019540",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-583-1",
          "name" : "USN-583-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0768/references",
          "name" : "ADV-2008-0768",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41011",
          "name" : "evolution-emfmultipart-format-string(41011)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2310",
          "name" : "https://issues.rpath.com/browse/RPL-2310",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10701",
          "name" : "oval:org.mitre.oval:def:10701",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00190.html",
          "name" : "FEDORA-2008-2290",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00195.html",
          "name" : "FEDORA-2008-2292",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a crafted encrypted message, as demonstrated using the Version field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:gnome:evolution:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "2.12.3"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-06T00:44Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0073",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xine",
            "product" : {
              "product_data" : [ {
                "product_name" : "xine-lib",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.10.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00008.html",
          "name" : "SUSE-SR:2008:007",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html",
          "name" : "SUSE-SR:2008:012",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28694",
          "name" : "28694",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29392",
          "name" : "29392",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29472",
          "name" : "29472",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29503",
          "name" : "29503",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29578",
          "name" : "29578",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29601",
          "name" : "29601",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29740",
          "name" : "29740",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29766",
          "name" : "29766",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29800",
          "name" : "29800",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30581",
          "name" : "30581",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31372",
          "name" : "31372",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31393",
          "name" : "31393",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/secunia_research/2008-10/",
          "name" : "http://secunia.com/secunia_research/2008-10/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200804-25.xml",
          "name" : "GLSA-200804-25",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200808-01.xml",
          "name" : "GLSA-200808-01",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=585488&group_id=9655",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=585488&group_id=9655",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://wiki.videolan.org/Changelog/0.8.6f",
          "name" : "http://wiki.videolan.org/Changelog/0.8.6f",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1536",
          "name" : "DSA-1536",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1543",
          "name" : "DSA-1543",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:178",
          "name" : "MDVSA-2008:178",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:219",
          "name" : "MDVSA-2008:219",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28312",
          "name" : "28312",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019682",
          "name" : "1019682",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.slackware.org/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.392408",
          "name" : "SSA:2008-089-03",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-635-1",
          "name" : "USN-635-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.videolan.org/security/sa0803.php",
          "name" : "http://www.videolan.org/security/sa0803.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0923",
          "name" : "ADV-2008-0923",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0985",
          "name" : "ADV-2008-0985",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://xinehq.de/index.php/news",
          "name" : "http://xinehq.de/index.php/news",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41339",
          "name" : "xinelib-sdpplinparse-bo(41339)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00143.html",
          "name" : "FEDORA-2008-2945",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00456.html",
          "name" : "FEDORA-2008-2569",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:fedora:8:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:xine:xine-lib:1.1.10.1:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-24T22:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0074",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_information_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_information_services",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          }, {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28849",
          "name" : "28849",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27101",
          "name" : "27101",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019384",
          "name" : "1019384",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0507/references",
          "name" : "ADV-2008-0507",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-005",
          "name" : "MS08-005",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5389",
          "name" : "oval:org.mitre.oval:def:5389",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\\Root, or WWWRoot folders."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_information_server:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_information_server:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_information_server:6.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_information_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_information_services:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T21:00Z",
    "lastModifiedDate" : "2019-07-03T17:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0075",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_information_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          }, {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28893",
          "name" : "28893",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27676",
          "name" : "27676",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019385",
          "name" : "1019385",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0508/references",
          "name" : "ADV-2008-0508",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-006",
          "name" : "MS08-006",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5308",
          "name" : "oval:org.mitre.oval:def:5308",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary code via crafted inputs to ASP pages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_information_server:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_information_server:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_information_server:6.0:beta:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T21:00Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0076",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28903",
          "name" : "28903",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27668",
          "name" : "27668",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019379",
          "name" : "1019379",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0512/references",
          "name" : "ADV-2008-0512",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-010",
          "name" : "MS08-010",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5487",
          "name" : "oval:org.mitre.oval:def:5487",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via crafted HTML layout combinations, aka \"HTML Rendering Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.01:windows_2000_sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1_itanium:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:windows_xp_sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7:windows_server_2003_sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7:windows_xp_sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_sp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_sp2_itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_x64_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_x64_edition_sp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_xp_professional_x64_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_xp_professional_x64_edition_sp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_sp1_itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_sp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_sp2_itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_x64_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_x64_edition_sp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_vista:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_vista_x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_xp_professional_x64_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_xp_professional_x64_edition_sp2:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T23:00Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0077",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=661",
          "name" : "20080212 Microsoft Internet Explorer Property Memory Corruption Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28903",
          "name" : "28903",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/228569",
          "name" : "VU#228569",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488048/100/0/threaded",
          "name" : "20080213 ZDI-08-006: Microsoft Internet Explorer SVG animateMotion.by Code Execution Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27666",
          "name" : "27666",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019380",
          "name" : "1019380",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0512/references",
          "name" : "ADV-2008-0512",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-006.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-006.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-010",
          "name" : "MS08-010",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5396",
          "name" : "oval:org.mitre.oval:def:5396",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, as demonstrated using the by property of an animateMotion SVG element, aka \"Property Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:sp1:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:gold:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:sp2:x64:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:gold:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:sp2:x64:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T23:00Z",
    "lastModifiedDate" : "2019-02-26T14:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0078",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "activex",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28903",
          "name" : "28903",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27689",
          "name" : "27689",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019381",
          "name" : "1019381",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0512/references",
          "name" : "ADV-2008-0512",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-010",
          "name" : "MS08-010",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4904",
          "name" : "oval:org.mitre.oval:def:4904",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via a crafted image, aka \"Argument Handling Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:activex:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.01:windows_2000_sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1_itanium:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:windows_xp_sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7:windows_server_2003_sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7:windows_xp_sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_sp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_sp2_itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_x64_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_server_2003_x64_edition_sp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_xp_professional_x64_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:6:*:windows_xp_professional_x64_edition_sp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_sp1_itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_sp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_sp2_itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_x64_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_server_2003_x64_edition_sp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_vista:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_vista_x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_xp_professional_x64_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:windows_xp_professional_x64_edition_sp2:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T23:00Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0079",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2008. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0080",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "webdav_mini-redirector",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28894",
          "name" : "28894",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27670",
          "name" : "27670",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019372",
          "name" : "1019372",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0509/references",
          "name" : "ADV-2008-0509",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-007",
          "name" : "MS08-007",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5381",
          "name" : "oval:org.mitre.oval:def:5381",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the WebDAV Mini-Redirector in Microsoft Windows XP SP2, Server 2003 SP1 and SP2, and Vista allows remote attackers to execute arbitrary code via a crafted WebDAV response."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:2003:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2003:2003:sp1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:*:x64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:webdav_mini-redirector:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T23:00Z",
    "lastModifiedDate" : "2018-10-30T16:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0081",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120585858807305&w=2",
          "name" : "SSRT080028",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28506",
          "name" : "28506",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019200",
          "name" : "1019200",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.microsoft.com/technet/security/advisory/947563.mspx",
          "name" : "947563",
          "refsource" : "MSKB",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27305",
          "name" : "27305",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-071A.html",
          "name" : "TA08-071A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0146",
          "name" : "ADV-2008-0146",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0846/references",
          "name" : "ADV-2008-0846",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-014",
          "name" : "MS08-014",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39699",
          "name" : "microsoft-excel-unspecified-code-execution(39699)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5546",
          "name" : "oval:org.mitre.oval:def:5546",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka \"Macro Validation Vulnerability,\" a different vulnerability than CVE-2007-3490."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T23:00Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0082",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_messenger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=121915960406986&w=2",
          "name" : "HPSBST02360",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31446",
          "name" : "31446",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/495467/100/0/threaded",
          "name" : "20080814 Microsoft Windows Messenger Remote Illegal Access Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/30551",
          "name" : "30551",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020681",
          "name" : "1020681",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-225A.html",
          "name" : "TA08-225A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2354",
          "name" : "ADV-2008-2354",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-050",
          "name" : "MS08-050",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5995",
          "name" : "oval:org.mitre.oval:def:5995",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to control the Messenger application, and \"change state,\" obtain contact information, and establish audio or video connections without notification via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:windows_messenger:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:windows_messenger:5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-08-13T00:41Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0083",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120845064910729&w=2",
          "name" : "SSRT080048",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29712",
          "name" : "29712",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28551",
          "name" : "28551",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019799",
          "name" : "1019799",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-099A.html",
          "name" : "TA08-099A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1146/references",
          "name" : "ADV-2008-1146",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-022",
          "name" : "MS08-022",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5495",
          "name" : "oval:org.mitre.oval:def:5495",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:x64:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-08T23:05Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0084",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28828",
          "name" : "28828",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27634",
          "name" : "27634",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019383",
          "name" : "1019383",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0506/references",
          "name" : "ADV-2008-0506",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-004",
          "name" : "MS08-004",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5240",
          "name" : "oval:org.mitre.oval:def:5240",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the TCP/IP support in Microsoft Windows Vista allows remote DHCP servers to cause a denial of service (hang and restart) via a crafted DHCP packet."
        }, {
          "lang" : "en",
          "value" : "Apply patches.\r\n\r\nWindows Vista:\r\nhttp://www.microsoft.com/downloads/de...=8ce9608b-7049-47cd-adc4-22a803877d33\r\n\r\nWindows Vista x64 Edition:\r\nhttp://www.microsoft.com/downloads/de...=d7b9c3d1-9c23-4e05-bac6-d0b327feaf53"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T21:00Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0085",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "data_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sql_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sql_server_desktop_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "wmsde",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "wyukon",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/30970",
          "name" : "30970",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/516397/100/0/threaded",
          "name" : "20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020441",
          "name" : "1020441",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-190A.html",
          "name" : "TA08-190A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vmware.com/security/advisories/VMSA-2011-0003.html",
          "name" : "http://www.vmware.com/security/advisories/VMSA-2011-0003.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html",
          "name" : "http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2022/references",
          "name" : "ADV-2008-2022",
          "refsource" : "VUPEN",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-040",
          "name" : "MS08-040",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14213",
          "name" : "oval:org.mitre.oval:def:14213",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 does not initialize memory pages when reallocating memory, which allows database operators to obtain sensitive information (database contents) via unknown vectors related to memory page reuse."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:data_engine:1.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:7.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2000:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2000:sp4:*:*:*:*:itanium:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp1:*:*:*:*:itanium:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp1:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp2:*:*:*:*:itanium:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp2:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server_desktop_engine:2000:sp4:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:wmsde:2000:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:wyukon:*:sp2:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:-:sp1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:-:sp2:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:wmsde:2000:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:wyukon:*:sp2:*:*:*:*:x64:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-07-08T23:41Z",
    "lastModifiedDate" : "2019-02-28T00:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0086",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "data_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sql_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sql_server_desktop_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sql_server_express_edition",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/30970",
          "name" : "30970",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/494082/100/0/threaded",
          "name" : "20080708 Re: [Full-disclosure] iDefense Security Advisory 07.08.08: Microsoft SQL Server Restore Integer Underflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/516397/100/0/threaded",
          "name" : "20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020441",
          "name" : "1020441",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-190A.html",
          "name" : "TA08-190A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vmware.com/security/advisories/VMSA-2011-0003.html",
          "name" : "http://www.vmware.com/security/advisories/VMSA-2011-0003.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html",
          "name" : "http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2022/references",
          "name" : "ADV-2008-2022",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-040",
          "name" : "MS08-040",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14052",
          "name" : "oval:org.mitre.oval:def:14052",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:data_engine:1.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:7.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2000:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server_desktop_engine:2000:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server_express_edition:2005:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-07-08T23:41Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0087",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows-nt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120845064910729&w=2",
          "name" : "SSRT080048",
          "refsource" : "HP",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29696",
          "name" : "29696",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/490575/100/0/threaded",
          "name" : "20080408 Microsoft Windows DNS Stub Resolver Cache Poisoning (MS08-020)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28553",
          "name" : "28553",
          "refsource" : "BID",
          "tags" : [ "Patch", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019802",
          "name" : "1019802",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.trusteer.com/docs/windowsresolver.html",
          "name" : "http://www.trusteer.com/docs/windowsresolver.html",
          "refsource" : "MISC",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-099A.html",
          "name" : "TA08-099A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1144/references",
          "name" : "ADV-2008-1144",
          "refsource" : "VUPEN",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-020",
          "name" : "MS08-020",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5314",
          "name" : "oval:org.mitre.oval:def:5314",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:xp:sp2:*:*:pro:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:itanium:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:itanium:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 8.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-08T23:05Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0088",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sp2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28764",
          "name" : "28764",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27638",
          "name" : "27638",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019382",
          "name" : "1019382",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0505/references",
          "name" : "ADV-2008-0505",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-003",
          "name" : "MS08-003",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5181",
          "name" : "oval:org.mitre.oval:def:5181",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T21:00Z",
    "lastModifiedDate" : "2019-04-30T14:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0089",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clip-share",
            "product" : {
              "product_data" : [ {
                "product_name" : "clipshare",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/40077",
          "name" : "40077",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28313",
          "name" : "28313",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27108",
          "name" : "27108",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39364",
          "name" : "clipshare-uprofile-sql-injection(39364)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4830",
          "name" : "4830",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in uprofile.php in ClipShare allows remote attackers to execute arbitrary SQL commands via the UID parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clip-share:clipshare:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-04T01:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0090",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "divx",
            "product" : {
              "product_data" : [ {
                "product_name" : "divx_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27106",
          "name" : "27106",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39386",
          "name" : "divxwebplayer-npUpload-dos(39386)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4829",
          "name" : "4829",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long argument to the SetPassword method."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:divx:divx_player:6.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-04T01:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0091",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "agency4net",
            "product" : {
              "product_data" : [ {
                "product_name" : "webftp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28309",
          "name" : "28309",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2008-January/001865.html",
          "name" : "20080104 true: AGENCY4NET WEBFTP directory traversal; deletion possible",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27092",
          "name" : "27092",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0051",
          "name" : "ADV-2008-0051",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39343",
          "name" : "agency4net-download2-directory-traversal(39343)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4828",
          "name" : "4828",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in download2.php in AGENCY4NET WEBFTP 1 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the file parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:agency4net:webftp:1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-04T01:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0092",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpwebsite",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpwebsite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://phpwebsite.appstate.edu/blog/2143",
          "name" : "http://phpwebsite.appstate.edu/blog/2143",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28303",
          "name" : "28303",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3511",
          "name" : "3511",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485704/100/0/threaded",
          "name" : "20080101 Cross-Site Scripting (XSS) in phpWebSite 1.4.0 search",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27090",
          "name" : "27090",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39391",
          "name" : "phpwebsite-search-xss(39391)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpwebsite:phpwebsite:1.4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-04T01:46Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0093",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "eticket",
            "product" : {
              "product_data" : [ {
                "product_name" : "eticket",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.6_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.6_rc3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28331",
          "name" : "28331",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.digitrustgroup.com/advisories/web-application-security-eticket.html",
          "name" : "http://www.digitrustgroup.com/advisories/web-application-security-eticket.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27130",
          "name" : "27130",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39400",
          "name" : "eticket-name-subject-xss(39400)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in eTicket 1.5.5.2, and 1.5.6 RC2 and RC3, allow remote attackers to inject arbitrary web script or HTML via the (1) Name and (2) Subject parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eticket:eticket:1.5.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eticket:eticket:1.5.6_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eticket:eticket:1.5.6_rc3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-08T01:46Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0094",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "modxcms",
            "product" : {
              "product_data" : [ {
                "product_name" : "modxcms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://modxcms.com/forums/index.php/topic,21290.0.html",
          "name" : "http://modxcms.com/forums/index.php/topic,21290.0.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28220",
          "name" : "28220",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3522",
          "name" : "3522",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485707/100/0/threaded",
          "name" : "20080102 MODx CMS Source code disclosure, local file inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27096",
          "name" : "27096",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27097",
          "name" : "27097",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39352",
          "name" : "modx-ajaxsearch-file-include(39352)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the as_language parameter to assets/snippets/AjaxSearch/AjaxSearch.php, reached through index-ajax.php; and (2) read arbitrary local files via a .. (dot dot) in the file parameter to assets/js/htcmime.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:modxcms:modxcms:0.9.6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T02:46Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0095",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "asterisk",
            "product" : {
              "product_data" : [ {
                "product_name" : "asterisk_appliance_developer_kit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4_revision_95945",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "asterisk_business_edition",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "c.1.0beta7",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "asterisknow",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "beta_6",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "open_source",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.16",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "s800i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.3.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.digium.com/view.php?id=11637",
          "name" : "http://bugs.digium.com/view.php?id=11637",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://downloads.digium.com/pub/security/AST-2008-001.html",
          "name" : "http://downloads.digium.com/pub/security/AST-2008-001.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28299",
          "name" : "28299",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28312",
          "name" : "28312",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3520",
          "name" : "3520",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485727/100/0/threaded",
          "name" : "20080102 AST-2008-001: Crash from transfer using BYE with Also header",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27110",
          "name" : "27110",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019152",
          "name" : "1019152",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0019",
          "name" : "ADV-2008-0019",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39361",
          "name" : "asterisk-bye-also-dos(39361)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00166.html",
          "name" : "FEDORA-2008-0198",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00167.html",
          "name" : "FEDORA-2008-0199",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x before 1.0.3.4 allows remote attackers to cause a denial of service (daemon crash) via a BYE message with an Also (Also transfer) header, which triggers a NULL pointer dereference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4_revision_95945"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:asterisk:asterisk_business_edition:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "c.1.0beta7"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:asterisk:asterisknow:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "beta_6"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:asterisk:open_source:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4.16"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:asterisk:s800i:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.3.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T02:46Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0096",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "georgia_softworks",
            "product" : {
              "product_data" : [ {
                "product_name" : "ssh2_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.01.0003",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/gswsshit-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/gswsshit-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28307",
          "name" : "28307",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3517",
          "name" : "3517",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485725/100/0/threaded",
          "name" : "20080102 Multiple vulnerabilities in Georgia SoftWorks SSH2 Server 7.01.0003",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27103",
          "name" : "27103",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to execute arbitrary code via a (1) a long username, which triggers an overflow in the log function; or (2) a long password."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:georgia_softworks:ssh2_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.01.0003"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T02:46Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0097",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "georgia_softworks",
            "product" : {
              "product_data" : [ {
                "product_name" : "ssh2_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.01.0003",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/gswsshit-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/gswsshit-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28307",
          "name" : "28307",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3517",
          "name" : "3517",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485725/100/0/threaded",
          "name" : "20080102 Multiple vulnerabilities in Georgia SoftWorks SSH2 Server 7.01.0003",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the log function in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username field, as demonstrated by a certain LoginPassword message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:georgia_softworks:ssh2_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.01.0003"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T02:46Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0098",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "realnetworks",
            "product" : {
              "product_data" : [ {
                "product_name" : "realplayer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11_build_6.0.14.748",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://gleg.net/realplayer11.html",
          "name" : "http://gleg.net/realplayer11.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.immunitysec.com/pipermail/dailydave/2008-January/004811.html",
          "name" : "[Dailydave] 20080101 0day RealPlayer exploit demo",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28276",
          "name" : "28276",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27091",
          "name" : "27091",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019153",
          "name" : "1019153",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/current/index.html#public_exploit_code_for_realplayer",
          "name" : "http://www.us-cert.gov/current/index.html#public_exploit_code_for_realplayer",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0016",
          "name" : "ADV-2008-0016",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in RealPlayer 11 build 6.0.14.748 allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: As of 20080103, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:realnetworks:realplayer:11_build_6.0.14.748:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T02:46Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0099",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "myphp_forum",
            "product" : {
              "product_data" : [ {
                "product_name" : "myphp_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27118",
          "name" : "27118",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4831",
          "name" : "4831",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:myphp_forum:myphp_forum:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T02:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0100",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "white_dune",
            "product" : {
              "product_data" : [ {
                "product_name" : "white_dune",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.29beta791",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/whitedunboffs-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/whitedunboffs-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28287",
          "name" : "28287",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3516",
          "name" : "3516",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://vrml.cip.ica.uni-stuttgart.de/dune/news.html",
          "name" : "http://vrml.cip.ica.uni-stuttgart.de/dune/news.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485724/100/0/threaded",
          "name" : "20080102 Buffer-overflow and format string in White_Dune 0.29beta791",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27102",
          "name" : "27102",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39385",
          "name" : "whitedune-sceneerrorf-bo(39385)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the Scene::errorf function in Scene.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via a long string in a .WRL file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:white_dune:white_dune:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.29beta791"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T02:46Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0101",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "white_dune",
            "product" : {
              "product_data" : [ {
                "product_name" : "white_dune",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.29beta791",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/whitedunboffs-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/whitedunboffs-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28287",
          "name" : "28287",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3516",
          "name" : "3516",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://vrml.cip.ica.uni-stuttgart.de/dune/news.html",
          "name" : "http://vrml.cip.ica.uni-stuttgart.de/dune/news.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485724/100/0/threaded",
          "name" : "20080102 Buffer-overflow and format string in White_Dune 0.29beta791",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27102",
          "name" : "27102",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39388",
          "name" : "whitedune-swdegugf-format-string(39388)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the swDebugf function in DuneApp.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a .WRL file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:white_dune:white_dune:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.29beta791"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T02:46Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0102",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "publisher",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28906",
          "name" : "28906",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27739",
          "name" : "27739",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019376",
          "name" : "1019376",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0514/references",
          "name" : "ADV-2008-0514",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-012",
          "name" : "MS08-012",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5305",
          "name" : "oval:org.mitre.oval:def:5305",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid \"memory values,\" aka \"Publisher Invalid Memory Reference Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:publisher:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:publisher:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:publisher:2003:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T23:00Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0103",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28909",
          "name" : "28909",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27738",
          "name" : "27738",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019375",
          "name" : "1019375",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0515/references",
          "name" : "ADV-2008-0515",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-013",
          "name" : "MS08-013",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5407",
          "name" : "oval:org.mitre.oval:def:5407",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a \"memory handling error,\" aka \"Microsoft Office Execution Jump Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac\\+os:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-13T00:00Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0104",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "publisher",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28906",
          "name" : "28906",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27740",
          "name" : "27740",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019377",
          "name" : "1019377",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0514/references",
          "name" : "ADV-2008-0514",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-012",
          "name" : "MS08-012",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4547",
          "name" : "oval:org.mitre.oval:def:4547",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka \"Publisher Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:publisher:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T23:00Z",
    "lastModifiedDate" : "2018-10-30T16:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0105",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28904",
          "name" : "28904",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27658",
          "name" : "27658",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019387",
          "name" : "1019387",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0513/references",
          "name" : "ADV-2008-0513",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-011",
          "name" : "MS08-011",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5009",
          "name" : "oval:org.mitre.oval:def:5009",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka \"Microsoft Works File Converter Index Table Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2005:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T23:00Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0106",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "data_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sql_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sql_server_desktop_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sql_server_express_edition",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/30970",
          "name" : "30970",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/494082/100/0/threaded",
          "name" : "20080708 Re: [Full-disclosure] iDefense Security Advisory 07.08.08: Microsoft SQL Server Restore Integer Underflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/516397/100/0/threaded",
          "name" : "20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020441",
          "name" : "1020441",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-190A.html",
          "name" : "TA08-190A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vmware.com/security/advisories/VMSA-2011-0003.html",
          "name" : "http://www.vmware.com/security/advisories/VMSA-2011-0003.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html",
          "name" : "http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2022/references",
          "name" : "ADV-2008-2022",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-040",
          "name" : "MS08-040",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13785",
          "name" : "oval:org.mitre.oval:def:13785",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:data_engine:1.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:7.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2000:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server_desktop_engine:2000:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server_express_edition:2005:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-07-08T23:41Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0107",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "data_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sql_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sql_server_desktop_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "wmsde",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "wyukon",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=723",
          "name" : "20080708 Microsoft SQL Server Restore Integer Underflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30970",
          "name" : "30970",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.insomniasec.com/advisories/ISVA-080709.1.htm",
          "name" : "http://www.insomniasec.com/advisories/ISVA-080709.1.htm",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/494082/100/0/threaded",
          "name" : "20080708 Re: [Full-disclosure] iDefense Security Advisory 07.08.08: Microsoft SQL Server Restore Integer Underflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/516397/100/0/threaded",
          "name" : "20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/30119",
          "name" : "30119",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020441",
          "name" : "1020441",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-190A.html",
          "name" : "TA08-190A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vmware.com/security/advisories/VMSA-2011-0003.html",
          "name" : "http://www.vmware.com/security/advisories/VMSA-2011-0003.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html",
          "name" : "http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2022/references",
          "name" : "ADV-2008-2022",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-040",
          "name" : "MS08-040",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13936",
          "name" : "oval:org.mitre.oval:def:13936",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 allows remote authenticated users to execute arbitrary code via a (1) SMB or (2) WebDAV pathname for an on-disk file (aka stored backup file) with a crafted record size value, which triggers a heap-based buffer overflow, aka \"SQL Server Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:data_engine:1.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:7.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2000:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2000:sp4:itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp1:itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp1:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp2:itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server:2005:sp2:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sql_server_desktop_engine:2000:sp4:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:wmsde:2000:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:wyukon:*:sp2:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:wmsde:2000:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:wyukon:*:sp2:x64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:wyukon:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:wyukon:*:sp2:x64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:*:x32:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:*:x64:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-07-08T23:41Z",
    "lastModifiedDate" : "2019-02-26T14:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0108",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=660",
          "name" : "20080208 Microsoft Office Works Converter Stack-based Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28904",
          "name" : "28904",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27659",
          "name" : "27659",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019388",
          "name" : "1019388",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0513/references",
          "name" : "ADV-2008-0513",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-011",
          "name" : "MS08-011",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5202",
          "name" : "oval:org.mitre.oval:def:5202",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5107",
          "name" : "5107",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka \"Microsoft Works File Converter Field Length Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2005:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T23:00Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0109",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28901",
          "name" : "28901",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/692417",
          "name" : "VU#692417",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488071/100/0/threaded",
          "name" : "20080213 [Reversemode Advisory] February Advisories : Microsoft Word 2003 + Fortinet Forticlient",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27656",
          "name" : "27656",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019374",
          "name" : "1019374",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0511/references",
          "name" : "ADV-2008-0511",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-009",
          "name" : "MS08-009",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5073",
          "name" : "oval:org.mitre.oval:def:5073",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T23:00Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0110",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120585858807305&w=2",
          "name" : "SSRT080028",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29320",
          "name" : "29320",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/393305",
          "name" : "VU#393305",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28147",
          "name" : "28147",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019579",
          "name" : "1019579",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-071A.html",
          "name" : "TA08-071A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0847/references",
          "name" : "ADV-2008-0847",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-015",
          "name" : "MS08-015",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5278",
          "name" : "oval:org.mitre.oval:def:5278",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers to execute arbitrary code via a crafted mailto URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-11T23:44Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0111",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_compatibility_pack_for_word_excel_ppt_2007",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          }, {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120585858807305&w=2",
          "name" : "SSRT080028",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28094",
          "name" : "28094",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019582",
          "name" : "1019582",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-071A.html",
          "name" : "TA08-071A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0846/references",
          "name" : "ADV-2008-0846",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-014",
          "name" : "MS08-014",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5114",
          "name" : "oval:org.mitre.oval:def:5114",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted data validation records, aka \"Excel Data Validation Record Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-11T23:44Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0112",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2008",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120585858807305&w=2",
          "name" : "SSRT080028",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28095",
          "name" : "28095",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019583",
          "name" : "1019583",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-071A.html",
          "name" : "TA08-071A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0846/references",
          "name" : "ADV-2008-0846",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-014",
          "name" : "MS08-014",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5284",
          "name" : "oval:org.mitre.oval:def:5284",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Excel 2000 SP3, and Office for Mac 2004 and 2008 allows user-assisted remote attackers to execute arbitrary code via a crafted .SLK file that is not properly handled when importing the file, aka \"Excel File Import Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2008:*:mac:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-11T23:44Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0113",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          }, {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120585858807305&w=2",
          "name" : "SSRT080028",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29321",
          "name" : "29321",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489415/100/0/threaded",
          "name" : "20080311 ZDI-08-008: Microsoft Excel BIFF File Format Cell Record Parsing Memory Corruption Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019578",
          "name" : "1019578",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-071A.html",
          "name" : "TA08-071A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0848/references",
          "name" : "ADV-2008-0848",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-008",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-008",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-016",
          "name" : "MS08-016",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5421",
          "name" : "oval:org.mitre.oval:def:5421",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an \"allocation error,\" aka \"Microsoft Office Cell Parsing Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-11T23:44Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0114",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120585858807305&w=2",
          "name" : "SSRT080028",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28166",
          "name" : "28166",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019584",
          "name" : "1019584",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-071A.html",
          "name" : "TA08-071A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0846/references",
          "name" : "ADV-2008-0846",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-014",
          "name" : "MS08-014",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5456",
          "name" : "oval:org.mitre.oval:def:5456",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via crafted Style records that trigger memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-11T23:44Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0115",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_compatibility_pack_for_word_excel_ppt_2007",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120585858807305&w=2",
          "name" : "SSRT080028",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28167",
          "name" : "28167",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019585",
          "name" : "1019585",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-071A.html",
          "name" : "TA08-071A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0846/references",
          "name" : "ADV-2008-0846",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-014",
          "name" : "MS08-014",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5512",
          "name" : "oval:org.mitre.oval:def:5512",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via malformed formulas, aka \"Excel Formula Parsing Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-11T23:44Z",
    "lastModifiedDate" : "2018-10-12T21:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0116",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2008",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_compatibility_pack_for_word_excel_ppt_2007",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          }, {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dvlabs.tippingpoint.com/advisory/TPTI-08-03",
          "name" : "http://dvlabs.tippingpoint.com/advisory/TPTI-08-03",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=120585858807305&w=2",
          "name" : "SSRT080028",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489430/100/0/threaded",
          "name" : "20080311 TPTI-08-03: Microsoft Excel Rich Text Memory Corruption Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28168",
          "name" : "28168",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019586",
          "name" : "1019586",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-071A.html",
          "name" : "TA08-071A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0846/references",
          "name" : "ADV-2008-0846",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-014",
          "name" : "MS08-014",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5212",
          "name" : "oval:org.mitre.oval:def:5212",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka \"Excel Rich Text Validation Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2008:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-11T23:44Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0117",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "compatibility_pack_word_excel_powerpoint_2007",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2008",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120585858807305&w=2",
          "name" : "SSRT080028",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28170",
          "name" : "28170",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019587",
          "name" : "1019587",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-071A.html",
          "name" : "TA08-071A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0846/references",
          "name" : "ADV-2008-0846",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-014",
          "name" : "MS08-014",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5508",
          "name" : "oval:org.mitre.oval:def:5508",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute arbitrary code via crafted conditional formatting values, aka \"Excel Conditional Formatting Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:compatibility_pack_word_excel_powerpoint_2007:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2008:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-11T23:44Z",
    "lastModifiedDate" : "2018-10-12T21:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0118",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120585858807305&w=2",
          "name" : "SSRT080028",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29321",
          "name" : "29321",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28146",
          "name" : "28146",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019578",
          "name" : "1019578",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-071A.html",
          "name" : "TA08-071A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0848/references",
          "name" : "ADV-2008-0848",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-016",
          "name" : "MS08-016",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5190",
          "name" : "oval:org.mitre.oval:def:5190",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an \"allocation error,\" aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-11T23:44Z",
    "lastModifiedDate" : "2018-10-12T21:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0119",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007_sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=121129490723574&w=2",
          "name" : "SSRT080071",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30150",
          "name" : "30150",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/492073/100/0/threaded",
          "name" : "20080514 Microsoft Office Publisher PUB File Parsing Remote Memory Corruption Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29158",
          "name" : "29158",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020015",
          "name" : "1020015",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-134A.html",
          "name" : "TA08-134A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1505/references",
          "name" : "ADV-2008-1505",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-027",
          "name" : "MS08-027",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5303",
          "name" : "oval:org.mitre.oval:def:5303",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka \"Publisher Object Handler Validation Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2007_sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-05-13T22:20Z",
    "lastModifiedDate" : "2018-10-15T21:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0120",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office_powerpoint_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=739",
          "name" : "20080812 Microsoft PowerPoint Viewer 2003 Cstring Integer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=121915960406986&w=2",
          "name" : "HPSBST02360",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31453",
          "name" : "31453",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/30552",
          "name" : "30552",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020676",
          "name" : "1020676",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-225A.html",
          "name" : "TA08-225A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2355",
          "name" : "ADV-2008-2355",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-051",
          "name" : "MS08-051",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5768",
          "name" : "oval:org.mitre.oval:def:5768",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka \"Memory Allocation Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_powerpoint_viewer:2003:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-08-13T00:41Z",
    "lastModifiedDate" : "2018-10-12T21:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0121",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office_powerpoint_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=738",
          "name" : "20080812 Microsoft PowerPoint Viewer 2003 Out of Bounds Array Index Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=121915960406986&w=2",
          "name" : "HPSBST02360",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31453",
          "name" : "31453",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/30554",
          "name" : "30554",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020676",
          "name" : "1020676",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-225A.html",
          "name" : "TA08-225A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2355",
          "name" : "ADV-2008-2355",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-051",
          "name" : "MS08-051",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5724",
          "name" : "oval:org.mitre.oval:def:5724",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "A \"memory calculation error\" in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with an invalid picture index that triggers memory corruption, aka \"Memory Calculation Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_powerpoint_viewer:2003:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-08-13T00:41Z",
    "lastModifiedDate" : "2018-10-12T21:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0122",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "isc",
            "product" : {
              "product_data" : [ {
                "product_name" : "bind",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.4.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html",
          "name" : "SUSE-SR:2008:006",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28367",
          "name" : "28367",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28429",
          "name" : "28429",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28487",
          "name" : "28487",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28579",
          "name" : "28579",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29161",
          "name" : "29161",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29323",
          "name" : "29323",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30313",
          "name" : "30313",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30538",
          "name" : "30538",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30718",
          "name" : "30718",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://security.freebsd.org/advisories/FreeBSD-SA-08:02.libc.asc",
          "name" : "FreeBSD-SA-08:02",
          "refsource" : "FREEBSD",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238493-1",
          "name" : "238493",
          "refsource" : "SUNALERT",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2008-244.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2008-244.htm",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.isc.org/index.pl?/sw/bind/bind-security.php",
          "name" : "http://www.isc.org/index.pl?/sw/bind/bind-security.php",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/203611",
          "name" : "VU#203611",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0300.html",
          "name" : "RHSA-2008:0300",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487000/100/0/threaded",
          "name" : "20080124 rPSA-2008-0029-1 bind bind-utils",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27283",
          "name" : "27283",
          "refsource" : "BID",
          "tags" : [ "Patch", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019189",
          "name" : "1019189",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0193",
          "name" : "ADV-2008-0193",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0703",
          "name" : "ADV-2008-0703",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1743/references",
          "name" : "ADV-2008-1743",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX61&path=/200802/SECURITY/20080227/datafile123640&label=AIX%20libc%20inet_network%20buffer%20overflow",
          "name" : "http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX61&path=/200802/SECURITY/20080227/datafile123640&label=AIX%20libc%20inet_network%20buffer%20overflow",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4167",
          "name" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4167",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=429149",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=429149",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking", "Third Party Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39670",
          "name" : "freebsd-inetnetwork-bo(39670)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488",
          "name" : "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2169",
          "name" : "https://issues.rpath.com/browse/RPL-2169",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10190",
          "name" : "oval:org.mitre.oval:def:10190",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00781.html",
          "name" : "FEDORA-2008-0903",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00782.html",
          "name" : "FEDORA-2008-0904",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "9.4.2"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:-:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:p1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:p10:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:p11:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:p12:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:p4:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:p5:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:p6:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:p7:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:p8:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:p9:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:rc1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:rc2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:-:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:p1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:p10:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:p11:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:p12:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:p13:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:p14:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:p15:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:p2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:p3:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:p4:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:p5:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:p6:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:p7:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:p8:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:p9:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:rc2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.4:-:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.4:p1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.4:p10:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.4:p11:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.4:p2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.4:p3:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.4:p4:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.4:p5:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.4:p6:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.4:p7:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.4:p8:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.4:p9:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T02:00Z",
    "lastModifiedDate" : "2019-08-01T12:12Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0123",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "moodle",
            "product" : {
              "product_data" : [ {
                "product_name" : "moodle",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0202.html",
          "name" : "20080111 Cross site scripting (XSS) in Moodle 1.8.3",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://int21.de/cve/CVE-2008-0123-moodle.html",
          "name" : "http://int21.de/cve/CVE-2008-0123-moodle.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html",
          "name" : "SUSE-SR:2008:003",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28838",
          "name" : "28838",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486198/100/0/threaded",
          "name" : "20080111 Cross site scripting (XSS) in Moodle 1.8.3",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27259",
          "name" : "27259",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0164",
          "name" : "ADV-2008-0164",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39630",
          "name" : "moodle-install-xss(39630)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter.  NOTE: this issue only exists until the installation is complete."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.8.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-12T01:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0124",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "s9y",
            "product" : {
              "product_data" : [ {
                "product_name" : "serendipity",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5_pl1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6_pl1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6_pl2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6_pl3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7_beta2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7_beta3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7_beta4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8_beta5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8_beta6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8_beta_6_snapshot",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_beta2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_beta3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2__beta5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blog.s9y.org/archives/191-Serendipity-1.3-beta1-released.html",
          "name" : "http://blog.s9y.org/archives/191-Serendipity-1.3-beta1-released.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://int21.de/cve/CVE-2008-0124-s9y.html",
          "name" : "http://int21.de/cve/CVE-2008-0124-s9y.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29128",
          "name" : "29128",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29502",
          "name" : "29502",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1528",
          "name" : "DSA-1528",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28003",
          "name" : "28003",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019502",
          "name" : "1019502",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0700/references",
          "name" : "ADV-2008-0700",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40851",
          "name" : "serendipity-realname-username-xss(40851)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3-beta1 allows remote authenticated users to inject arbitrary web script or HTML via (1) the \"Real name\" field in Personal Settings, which is presented to readers of articles; or (2) a file upload, as demonstrated by a .htm, .html, or .js file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.5_pl1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.6_pl1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.6_pl2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.6_pl3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.6_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.6_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.7_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.7_beta2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.7_beta3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.7_beta4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.7_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.8_beta5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.8_beta6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.8_beta_6_snapshot:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:1.0_beta2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:1.0_beta3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:s9y:serendipity:1.2__beta5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-28T20:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0125",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpstats",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpstats",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1_alpha",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3765",
          "name" : "3765",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489722/100/0/threaded",
          "name" : "20080317 Cross Site Scripting (XSS) in phpstats 0.1_alpha, CVE-2008-0125",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28291",
          "name" : "28291",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41261",
          "name" : "phpstats-phpstats-xss(41261)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in phpstats.php in Michael Wagner phpstats 0.1 alpha allows remote attackers to inject arbitrary web script or HTML via the baseDir parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpstats:phpstats:0.1_alpha:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-24T22:44Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0127",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mcafee",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28408",
          "name" : "28408",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3530",
          "name" : "3530",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019170",
          "name" : "1019170",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485992/100/0/threaded",
          "name" : "20080109 [INFIGO 2008-01-06]: McAfee E-Business Server Remote Preauth Code Execution / DoS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486035/100/0/threaded",
          "name" : "20080109 [INFIGO-2008-01-06]: McAfee E-Business Server Remote Preauth Code Execution / DoS - Corrected",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27197",
          "name" : "27197",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0087",
          "name" : "ADV-2008-0087",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39561",
          "name" : "mcafee-ebusiness-authentication-packet-dos(39561)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39563",
          "name" : "mcafee-ebusiness-packet-code-execution(39563)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=614472&sliceId=SAL_Public&command=show&forward=nonthreadedKC&kcId=614472",
          "name" : "https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=614472&sliceId=SAL_Public&command=show&forward=nonthreadedKC&kcId=614472",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4878",
          "name" : "4878",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long initial authentication packet."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mcafee:e-business_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.5.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 8.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0128",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "tomcat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-16"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx",
          "name" : "http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://issues.apache.org/bugzilla/show_bug.cgi?id=41217",
          "name" : "http://issues.apache.org/bugzilla/show_bug.cgi?id=41217",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html",
          "name" : "SUSE-SR:2008:005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2008-0630.html",
          "name" : "RHSA-2008:0630",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28549",
          "name" : "28549",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28552",
          "name" : "28552",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29242",
          "name" : "29242",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31493",
          "name" : "31493",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/33668",
          "name" : "33668",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security-tracker.debian.net/tracker/CVE-2008-0128",
          "name" : "http://security-tracker.debian.net/tracker/CVE-2008-0128",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540",
          "name" : "http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1468",
          "name" : "DSA-1468",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0261.html",
          "name" : "RHSA-2008:0261",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/500396/100/0/threaded",
          "name" : "20090124 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/500412/100/0/threaded",
          "name" : "20090127 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27365",
          "name" : "27365",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0192",
          "name" : "ADV-2008-0192",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2009/0233",
          "name" : "ADV-2009-0233",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39804",
          "name" : "apache-singlesignon-information-disclosure(39804)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190319 svn commit: r1855831 [21/30] - in /tomcat/site/trunk: ./ docs/ xdocs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190325 svn commit: r1856174 [19/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200213 svn commit: r1873980 [24/34] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.5.20"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T02:00Z",
    "lastModifiedDate" : "2019-03-25T11:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0129",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "siteatschool",
            "product" : {
              "product_data" : [ {
                "product_name" : "siteatschool",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27120",
          "name" : "27120",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39417",
          "name" : "siteatschool-slideshowfull-sql-injection(39417)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4832",
          "name" : "4832",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attackers to execute arbitrary SQL commands via the album_name parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:siteatschool:siteatschool:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.3.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T11:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0130",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "instantsoftwares",
            "product" : {
              "product_data" : [ {
                "product_name" : "dating_site",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/39766",
          "name" : "39766",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28283",
          "name" : "28283",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39326",
          "name" : "dating-site-loginform-sql-injection(39326)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitrary SQL commands via the Username parameter, a different vulnerability than CVE-2007-6671.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:instantsoftwares:dating_site:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T11:46Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0131",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "instantsoftwares",
            "product" : {
              "product_data" : [ {
                "product_name" : "dating_site",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28283",
          "name" : "28283",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27121",
          "name" : "27121",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to inject arbitrary web script or HTML via the msg parameter, a different product than CVE-2006-6022.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:instantsoftwares:dating_site:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-08T11:46Z",
    "lastModifiedDate" : "2009-09-15T05:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0132",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pragma_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "fortressssh",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0_build_4_r_293",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/pragmassh-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/pragmassh-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://aluigi.org/poc/pragmassh.zip",
          "name" : "http://aluigi.org/poc/pragmassh.zip",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=119947184730448&w=2",
          "name" : "20080104 Some DoS in some telnet servers",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27141",
          "name" : "27141",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39354",
          "name" : "fortressssh-sshd-dos(39354)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the administrator to click in this window before terminating the sshd.exe process, which allows remote attackers to cause a denial of service (connection slot exhaustion) via a flood of SSH connections with long data objects, as demonstrated by (1) a long list of keys and (2) a long username."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pragma_systems:fortressssh:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0_build_4_r_293"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T11:46Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0133",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "thomas_perez",
            "product" : {
              "product_data" : [ {
                "product_name" : "tribisur",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28362",
          "name" : "28362",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27149",
          "name" : "27149",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39443",
          "name" : "tribisur-catmain-forum-sql-injection(39443)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4840",
          "name" : "4840",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to cat_main.php and the (2) cat parameter to forum.php in a liste action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:thomas_perez:tribisur:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T19:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0134",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "snitz_communications",
            "product" : {
              "product_data" : [ {
                "product_name" : "snitz_forums_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.06",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://hackerscenter.com/archive/view.asp?id=28145",
          "name" : "http://hackerscenter.com/archive/view.asp?id=28145",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28284",
          "name" : "28284",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt",
          "name" : "http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485836/100/200/threaded",
          "name" : "20080107 [HSC] Snitz Forums Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27162",
          "name" : "27162",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Forums/setup.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to inject arbitrary web script or HTML via the MAIL parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.1:sr4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.2.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.05:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.4.06"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-08T19:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0135",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "snitz_communications",
            "product" : {
              "product_data" : [ {
                "product_name" : "snitz_forums_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.06",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://hackerscenter.com/archive/view.asp?id=28145",
          "name" : "http://hackerscenter.com/archive/view.asp?id=28145",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt",
          "name" : "http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485836/100/200/threaded",
          "name" : "20080107 [HSC] Snitz Forums Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485894/100/200/threaded",
          "name" : "20080107 RE: [HSC] Snitz Forums Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Snitz Forums 2000 3.4.06 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum/snitz_forums_2000.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.1:sr4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.2.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.05:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.4.06"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T19:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0136",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "snitz_communications",
            "product" : {
              "product_data" : [ {
                "product_name" : "snitz_forums_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.4.05",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://hackerscenter.com/archive/view.asp?id=28145",
          "name" : "http://hackerscenter.com/archive/view.asp?id=28145",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt",
          "name" : "http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485836/100/200/threaded",
          "name" : "20080107 [HSC] Snitz Forums Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485894/100/200/threaded",
          "name" : "20080107 RE: [HSC] Snitz Forums Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the database path."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.05:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T19:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0137",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "snetworks",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_classifieds",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.vupen.com/english/advisories/2008/0053",
          "name" : "ADV-2008-0053",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39468",
          "name" : "snetworks-configinc-file-include(39468)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4838",
          "name" : "4838",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snetworks:php_classifieds:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T19:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0138",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xoops",
            "product" : {
              "product_data" : [ {
                "product_name" : "xoopsgallery_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.3_9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27155",
          "name" : "27155",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39461",
          "name" : "xoops-modgallery-zendhashkey-file-include(39461)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4847",
          "name" : "4847",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xoops:xoopsgallery_module:1.3.3_9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T19:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0139",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "loudblog",
            "product" : {
              "product_data" : [ {
                "product_name" : "loudblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28336",
          "name" : "28336",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27157",
          "name" : "27157",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39445",
          "name" : "loudblog-template-code-execution(39445)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4849",
          "name" : "4849",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:loudblog:loudblog:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.8.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T19:46Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0140",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "uebimiau",
            "product" : {
              "product_data" : [ {
                "product_name" : "webmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.attrition.org/pipermail/vim/2008-January/001867.html",
          "name" : "20080107 Uebimiau Web-Mail 2.7.10/2.7.2 Remote File Disclosure Vulnerability",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27154",
          "name" : "27154",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39460",
          "name" : "uebimiau-webmail-error-directory-traversal(39460)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4846",
          "name" : "4846",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in error.php in Uebimiau Webmail 2.7.10 and 2.7.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the selected_theme parameter, a different vector than CVE-2007-3172."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uebimiau:webmail:2.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uebimiau:webmail:2.7.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T19:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0141",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webportal",
            "product" : {
              "product_data" : [ {
                "product_name" : "webportal_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-255"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27145",
          "name" : "27145",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39486",
          "name" : "webportal-action-weak-security(39486)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4835",
          "name" : "4835",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webportal:webportal_cms:0.6_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T19:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0142",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webportal",
            "product" : {
              "product_data" : [ {
                "product_name" : "webportal_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://www.exploit-db.com/exploits/4835",
          "name" : "4835",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL commands via the user_name parameter to actions.php, and unspecified other vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webportal:webportal_cms:0.6_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T19:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0143",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "spacial_audio_solutions",
            "product" : {
              "product_data" : [ {
                "product_name" : "sam_broadcaster",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "samphpweb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28355",
          "name" : "28355",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27137",
          "name" : "27137",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.spacialaudio.com/news/index.html",
          "name" : "http://www.spacialaudio.com/news/index.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39397",
          "name" : "samPHPweb-db-file-include(39397)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4834",
          "name" : "4834",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in common/db.php in samPHPweb, possibly 4.2.2 and others, as provided with SAM Broadcaster, allows remote attackers to execute arbitrary PHP code via a URL in the commonpath parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spacial_audio_solutions:sam_broadcaster:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spacial_audio_solutions:samphpweb:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T19:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0144",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phprisk",
            "product" : {
              "product_data" : [ {
                "product_name" : "netrisk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=119955114428283&w=2",
          "name" : "20080105 NetRisk 1.9.7 Remote File Inclusion Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28328",
          "name" : "28328",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27136",
          "name" : "27136",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39419",
          "name" : "netrisk-index-file-include(39419)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4833",
          "name" : "4833",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.  NOTE: this can also be leveraged for local file inclusion using directory traversal sequences."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phprisk:netrisk:1.9.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T19:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0145",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.4.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          }, {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.php.net/bug.php?id=41655",
          "name" : "http://bugs.php.net/bug.php?id=41655",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28318",
          "name" : "28318",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28936",
          "name" : "28936",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.335136",
          "name" : "SSA:2008-045-03",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/ChangeLog-4.php",
          "name" : "http://www.php.net/ChangeLog-4.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/releases/4_4_8.php",
          "name" : "http://www.php.net/releases/4_4_8.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0059",
          "name" : "ADV-2008-0059",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39401",
          "name" : "php-glob-openbasedir-security-bypass(39401)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in glob in PHP before 4.4.8, when open_basedir is enabled, has unknown impact and attack vectors.  NOTE: this issue reportedly exists because of a regression related to CVE-2007-4663."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.4.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T19:46Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0146",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hughes_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "w3-msql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/51235",
          "name" : "51235",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28294",
          "name" : "28294",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3521",
          "name" : "3521",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485736/100/0/threaded",
          "name" : "20080103 xss in w3-msql error page",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27116",
          "name" : "27116",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the error page in W3-mSQL allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the top-level URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hughes_technologies:w3-msql:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-08T19:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0147",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "smallnuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "smallnuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28301",
          "name" : "28301",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27180",
          "name" : "27180",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39525",
          "name" : "smallnuke-index-sql-injection(39525)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4863",
          "name" : "4863",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smallnuke:smallnuke:2.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-09T00:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0148",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tutos",
            "product" : {
              "product_data" : [ {
                "product_name" : "tutos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28291",
          "name" : "28291",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39531",
          "name" : "tutos-cmd-command-execution(39531)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4861",
          "name" : "4861",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tutos:tutos:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-09T00:46Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0149",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tutos",
            "product" : {
              "product_data" : [ {
                "product_name" : "tutos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28291",
          "name" : "28291",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4861",
          "name" : "4861",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tutos:tutos:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-09T00:46Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0150",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aruba_networks",
            "product" : {
              "product_data" : [ {
                "product_name" : "aruba_mobility_controllers",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.8.11-fips",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "2.5.2.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.4.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28357",
          "name" : "28357",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3529",
          "name" : "3529",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.arubanetworks.com/support/alerts/aid-122207.asc",
          "name" : "http://www.arubanetworks.com/support/alerts/aid-122207.asc",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485831/100/0/threaded",
          "name" : "20080104 Aruba Mobility Controller User Authentication Vulnerability - Aruba Advisory ID: AID-122207",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27144",
          "name" : "27144",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the LDAP authentication feature in Aruba Mobility Controller 2.3.6.15, 2.5.2.11, 2.5.4.25, 2.5.5.7, 3.1.1.3, and 2.4.8.11-FIPS or earlier allows remote attackers to bypass authentication mechanisms and obtain management or VPN interface access."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aruba_networks:aruba_mobility_controllers:2.3.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aruba_networks:aruba_mobility_controllers:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.4.8.11-fips"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aruba_networks:aruba_mobility_controllers:2.5.2.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aruba_networks:aruba_mobility_controllers:2.5.4.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aruba_networks:aruba_mobility_controllers:2.5.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aruba_networks:aruba_mobility_controllers:3.1.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-09T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0151",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "foxitsoftware",
            "product" : {
              "product_data" : [ {
                "product_name" : "wac_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0.910",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/waccaz-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/waccaz-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://aluigi.altervista.org/adv/wachof-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/wachof-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28272",
          "name" : "28272",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3525",
          "name" : "3525",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485812/100/0/threaded",
          "name" : "20080104 Some DoS in some telnet servers",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488366/100/200/threaded",
          "name" : "20080219 Two heap overflow in Foxit WAC Server 2.0 Build 3503",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27142",
          "name" : "27142",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39427",
          "name" : "wacserver-option-dos(39427)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Telnet request with long options."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:foxitsoftware:wac_server:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:foxitsoftware:wac_server:2.1.0.910:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-09T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0152",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "seattle_lab_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "slnet_rf_telnet_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1.1.3758",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/slnetmsg-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/slnetmsg-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=119947184730448&w=2",
          "name" : "20080104 Some DoS in some telnet servers",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28316",
          "name" : "28316",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27134",
          "name" : "27134",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SLnet.exe in SeattleLab SLNet RF Telnet Server 4.1.1.3758 and earlier allows user-assisted remote attackers to cause a denial of service (crash) via unspecified telnet options, which triggers a NULL pointer dereference.  NOTE: the crash is not user-assisted when the server is running in debug mode."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:seattle_lab_software:slnet_rf_telnet_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.1.1.3758"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-09T00:46Z",
    "lastModifiedDate" : "2011-09-21T04:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0153",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pragma_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "pragma_telnetserver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.4.589",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/pragmatel-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/pragmatel-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=119947184730448&w=2",
          "name" : "20080104 Some DoS in some telnet servers",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27143",
          "name" : "27143",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39353",
          "name" : "pragmatelnetserver-telnetd-dos(39353)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and resource exhaustion) via a crafted TELOPT PRAGMA LOGON telnet option, which triggers a NULL pointer dereference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pragma_systems:pragma_telnetserver:7.0.4.589:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-09T00:46Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0154",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "evilboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "evilboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1a",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27190",
          "name" : "27190",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39529",
          "name" : "evilboard-index-sql-injection(39529)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4865",
          "name" : "4865",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to execute arbitrary SQL commands the c parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:evilboard:evilboard:0.1a:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-09T00:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0155",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "evilboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "evilboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1a",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27190",
          "name" : "27190",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39526",
          "name" : "evilboard-index-xss(39526)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4865",
          "name" : "4865",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitrary web script or HTML via the c parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:evilboard:evilboard:0.1a:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-09T00:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0156",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "million_dollar_script",
            "product" : {
              "product_data" : [ {
                "product_name" : "million_dollar_script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.14",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3524",
          "name" : "3524",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485882/100/0/threaded",
          "name" : "20080107 Million Dollar Script 2.0.14 Remote File Disclosure Vulnerability.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27174",
          "name" : "27174",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39492",
          "name" : "milliondollarscript-index-dir-traversal(39492)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Absolute path traversal vulnerability in index.php in Million Dollar Script 2.0.14 allows remote attackers to read arbitrary files via encoded \"/\" (%2F) sequences in the link parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:million_dollar_script:million_dollar_script:2.0.14:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-09T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0157",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "flexbb",
            "product" : {
              "product_data" : [ {
                "product_name" : "flexbb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6.3",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.0_10005_beta_release_1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28373",
          "name" : "28373",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27164",
          "name" : "27164",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39475",
          "name" : "flexbb-flexbbtempid-sql-injection(39475)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4858",
          "name" : "4858",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_temp_id parameter in a cookie."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:flexbb:flexbb:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.6.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:flexbb:flexbb:1.0_10005_beta_release_1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-09T00:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0158",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "shop-script",
            "product" : {
              "product_data" : [ {
                "product_name" : "shop-script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.org/0801-exploits/shopscript-disclose.txt",
          "name" : "http://packetstormsecurity.org/0801-exploits/shopscript-disclose.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27165",
          "name" : "27165",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39449",
          "name" : "shopscript-index-directory-traversal(39449)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4855",
          "name" : "4855",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary files via a .. (dot dot) in the aux_page parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shop-script:shop-script:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-09T00:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0159",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "eggblog",
            "product" : {
              "product_data" : [ {
                "product_name" : "eggblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28371",
          "name" : "28371",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27168",
          "name" : "27168",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39473",
          "name" : "eggblog-eggblogmail-sql-injection(39473)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4860",
          "name" : "4860",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the eggblogpassword parameter in a cookie."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eggblog:eggblog:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.1.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-09T00:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0162",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sam_lantinga",
            "product" : {
              "product_data" : [ {
                "product_name" : "splitvt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29064",
          "name" : "29064",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29080",
          "name" : "29080",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29190",
          "name" : "29190",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-05.xml",
          "name" : "GLSA-200803-05",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1500",
          "name" : "DSA-1500",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27936",
          "name" : "27936",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:alpha:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:amd64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:arm:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:hppa:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:ia-32:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:ia-64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:m68k:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:mips:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:mipsel:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:powerpc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:s-390:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:sparc:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:sam_lantinga:splitvt:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "1.6.6"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2008-09-05T21:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0163",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-59"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28875",
          "name" : "28875",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1494",
          "name" : "DSA-1494",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27704",
          "name" : "27704",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27798",
          "name" : "27798",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40486",
          "name" : "linux-kernel-proc-unauth-access(40486)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Linux kernel 2.6, when using vservers, allows local users to access resources of other vservers via a symlink attack in /proc."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T21:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0164",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "plone",
            "product" : {
              "product_data" : [ {
                "product_name" : "plone_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://plone.org/about/security/advisories/cve-2008-0164",
          "name" : "http://plone.org/about/security/advisories/cve-2008-0164",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29361",
          "name" : "29361",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3754",
          "name" : "3754",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.procheckup.com/Hacking_Plone_CMS.pdf",
          "name" : "http://www.procheckup.com/Hacking_Plone_CMS.pdf",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489544/100/0/threaded",
          "name" : "20080313 PR08-02: Plone CMS Security Research - the Art of Plowning",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41263",
          "name" : "plone-joinform-csrf(41263)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS 3.0.5 and 3.0.6 allow remote attackers to (1) add arbitrary accounts via the join_form page and (2) change the privileges of arbitrary groups via the prefs_groups_overview page."
        }, {
          "lang" : "en",
          "value" : "Must login to view link 1015140"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plone:plone_cms:3.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plone:plone_cms:3.0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-20T00:44Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0165",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ikiwiki",
            "product" : {
              "product_data" : [ {
                "product_name" : "ikiwiki",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.41",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475445",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475445",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://ikiwiki.info/security/#index31h2",
          "name" : "http://ikiwiki.info/security/#index31h2",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29907",
          "name" : "29907",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29932",
          "name" : "29932",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1553",
          "name" : "DSA-1553",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1297/references",
          "name" : "ADV-2008-1297",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41904",
          "name" : "ikiwiki-change-password-csrf(41904)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in Ikiwiki before 2.42 allows remote attackers to modify user preferences, including passwords, via the (1) preferences and (2) edit forms."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.41"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-21T13:05Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0166",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openssl_project",
            "product" : {
              "product_data" : [ {
                "product_name" : "openssl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.8c-1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8c-2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8c-3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8c-4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8c-5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8c-6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8c-7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8c-8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8c-9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8d-1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8d-2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8d-3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8d-4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8d-5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8d-6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8d-7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8d-8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8d-9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8e-1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8e-2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8e-3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8e-4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8e-5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8e-6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8e-7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8e-8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8e-9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8f-1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8f-2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8f-3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8f-4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8f-5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8f-6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8f-7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8f-8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8f-9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8g-1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8g-2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8g-3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8g-4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8g-5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8g-6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8g-7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8g-8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8g-9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-310"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://metasploit.com/users/hdm/tools/debian-openssl/",
          "name" : "http://metasploit.com/users/hdm/tools/debian-openssl/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30136",
          "name" : "30136",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30220",
          "name" : "30220",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30221",
          "name" : "30221",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30231",
          "name" : "30231",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30239",
          "name" : "30239",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30249",
          "name" : "30249",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/mailarchive/forum.php?thread_name=48367252.7070603%40shemesh.biz&forum_name=rsyncrypto-devel",
          "name" : "[rsyncrypto-devel] 20080523 Advisory - Rsyncrypto maybe affected from Debian OpenSSL reduced entropy problem",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1571",
          "name" : "DSA-1571",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1576",
          "name" : "DSA-1576",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/925211",
          "name" : "VU#925211",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/492112/100/0/threaded",
          "name" : "20080515 Debian generated SSH-Keys working exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29179",
          "name" : "29179",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020017",
          "name" : "1020017",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-612-1",
          "name" : "USN-612-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-612-2",
          "name" : "USN-612-2",
          "refsource" : "UBUNTU",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-612-3",
          "name" : "USN-612-3",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-612-4",
          "name" : "USN-612-4",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-612-7",
          "name" : "USN-612-7",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-137A.html",
          "name" : "TA08-137A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42375",
          "name" : "openssl-rng-weak-security(42375)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5622",
          "name" : "5622",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5632",
          "name" : "5632",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5720",
          "name" : "5720",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8c-1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8c-2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8c-3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8c-4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8c-5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8c-6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8c-7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8c-8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8c-9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8d-1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8d-2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8d-3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8d-4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8d-5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8d-6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8d-7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8d-8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8d-9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8e-1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8e-2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8e-3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8e-4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8e-5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8e-6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8e-7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8e-8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8e-9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8f-1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8f-2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8f-3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8f-4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8f-5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8f-6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8f-7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8f-8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8f-9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8g-1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8g-2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8g-3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8g-4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8g-5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8g-6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8g-7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8g-8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl_project:openssl:0.9.8g-9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-05-13T17:20Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0167",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gforge",
            "product" : {
              "product_data" : [ {
                "product_name" : "gforge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.14",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-59"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/30088",
          "name" : "30088",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30286",
          "name" : "30286",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch8.diff.gz",
          "name" : "http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch8.diff.gz",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1577",
          "name" : "DSA-1577",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29215",
          "name" : "29215",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1537/references",
          "name" : "ADV-2008-1537",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42456",
          "name" : "gforge-unspecified-symlink(42456)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:alpha:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:amd64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:arm:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:hppa:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:ia-32:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:ia-64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:m68k:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:mips:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:mipsel:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:powerpc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:s390:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:sparc:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:gforge:gforge:4.5.14:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-05-18T14:20Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0169",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ikiwiki",
            "product" : {
              "product_data" : [ {
                "product_name" : "ikiwiki",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.34.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.34.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.49",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.31.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.31.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.31.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.47",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=483770",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=483770",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://ikiwiki.info/news/version_2.48/index.html",
          "name" : "http://ikiwiki.info/news/version_2.48/index.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://ikiwiki.info/security/#index33h2",
          "name" : "http://ikiwiki.info/security/#index33h2",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30468",
          "name" : "30468",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2008/05/31/3",
          "name" : "[oss-security] 20080531 Re: CVE id request: ikiwiki",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29479",
          "name" : "29479",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1710",
          "name" : "ADV-2008-1710",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42798",
          "name" : "ikiwiki-openid-passwordauth-auth-bypass(42798)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any account for which an OpenID identity is configured and a password is not configured, by specifying an empty password during the login sequence."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.34.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.34.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.38:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.43:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.44:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.45:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.46:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.49:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.31.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.31.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.31.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.43:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.44:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.47:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-06-03T15:32Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0171",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "boost",
            "product" : {
              "product_data" : [ {
                "product_name" : "boost",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.34",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "boost_regex_library",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=205955",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=205955",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html",
          "name" : "SUSE-SR:2008:006",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28511",
          "name" : "28511",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28527",
          "name" : "28527",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28545",
          "name" : "28545",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28705",
          "name" : "28705",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28860",
          "name" : "28860",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28943",
          "name" : "28943",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29323",
          "name" : "29323",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/48099",
          "name" : "48099",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://svn.boost.org/trac/boost/changeset/42674",
          "name" : "http://svn.boost.org/trac/boost/changeset/42674",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://svn.boost.org/trac/boost/changeset/42745",
          "name" : "http://svn.boost.org/trac/boost/changeset/42745",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0063",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0063",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml",
          "name" : "GLSA-200802-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032",
          "name" : "MDVSA-2008:032",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488102/100/0/threaded",
          "name" : "20080213 rPSA-2008-0063-1 boost",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27325",
          "name" : "27325",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-570-1",
          "name" : "USN-570-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0249",
          "name" : "ADV-2008-0249",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2143",
          "name" : "https://issues.rpath.com/browse/RPL-2143",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html",
          "name" : "FEDORA-2008-0880",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:boost:boost:1.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:boost:boost:1.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:boost:boost_regex_library:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T23:00Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0172",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "boost",
            "product" : {
              "product_data" : [ {
                "product_name" : "boost",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.34",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=205955",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=205955",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html",
          "name" : "SUSE-SR:2008:006",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28511",
          "name" : "28511",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28527",
          "name" : "28527",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28545",
          "name" : "28545",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28705",
          "name" : "28705",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28860",
          "name" : "28860",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28943",
          "name" : "28943",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29323",
          "name" : "29323",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/48099",
          "name" : "48099",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://svn.boost.org/trac/boost/changeset/42674",
          "name" : "http://svn.boost.org/trac/boost/changeset/42674",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://svn.boost.org/trac/boost/changeset/42745",
          "name" : "http://svn.boost.org/trac/boost/changeset/42745",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0063",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0063",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml",
          "name" : "GLSA-200802-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032",
          "name" : "MDVSA-2008:032",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488102/100/0/threaded",
          "name" : "20080213 rPSA-2008-0063-1 boost",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27325",
          "name" : "27325",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-570-1",
          "name" : "USN-570-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0249",
          "name" : "ADV-2008-0249",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2143",
          "name" : "https://issues.rpath.com/browse/RPL-2143",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html",
          "name" : "FEDORA-2008-0880",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The get_repeat_type function in basic_regex_creator.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (NULL dereference and crash) via an invalid regular expression."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ubuntu:ubuntu_linux:6.06_lts:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ubuntu:ubuntu_linux:6.10:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ubuntu:ubuntu_linux:7.04:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ubuntu:ubuntu_linux:7.10:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:boost:boost:1.33:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:boost:boost:1.34:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T23:00Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0173",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gforge",
            "product" : {
              "product_data" : [ {
                "product_name" : "gforge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.6.99",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28395",
          "name" : "28395",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28451",
          "name" : "28451",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1459",
          "name" : "DSA-1459",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27266",
          "name" : "27266",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0115",
          "name" : "ADV-2008-0115",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39666",
          "name" : "gforge-multiple-sql-injection(39666)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gforge:gforge:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.6.99"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0174",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ge_fanuc",
            "product" : {
              "product_data" : [ {
                "product_name" : "proficy_real-time_information_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-310"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3590",
          "name" : "3590",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019273",
          "name" : "1019273",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.gefanuc.com/support/index?page=kbchannel&id=KB12459",
          "name" : "http://support.gefanuc.com/support/index?page=kbchannel&id=KB12459",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/180876",
          "name" : "VU#180876",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487075/100/0/threaded",
          "name" : "20080125 C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Authentication Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487244/100/0/threaded",
          "name" : "20080129 Re: C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Authentication Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/30754",
          "name" : "30754",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the passwords and gain privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ge_fanuc:proficy_real-time_information_portal:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T02:00Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0175",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ge_fanuc",
            "product" : {
              "product_data" : [ {
                "product_name" : "proficy_real-time_information_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28678",
          "name" : "28678",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3591",
          "name" : "3591",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://support.gefanuc.com/support/index?page=kbchannel&id=KB12460",
          "name" : "http://support.gefanuc.com/support/index?page=kbchannel&id=KB12460",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/339345",
          "name" : "VU#339345",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487079/100/0/threaded",
          "name" : "20080125 C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Arbitrary File Upload and Execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487242/100/0/threaded",
          "name" : "20080129 Re: C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Arbitrary File Upload and Execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27446",
          "name" : "27446",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019274",
          "name" : "1019274",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0307/references",
          "name" : "ADV-2008-0307",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unrestricted file upload vulnerability in GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to the main virtual directory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ge_fanuc:proficy_real-time_information_portal:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T02:00Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0176",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ge_fanuc",
            "product" : {
              "product_data" : [ {
                "product_name" : "cimplicity",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1_sp6_hf_010708_162517_6106",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "7.0_sim8",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28663",
          "name" : "28663",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3592",
          "name" : "3592",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://support.gefanuc.com/support/index?page=kbchannel&id=KB12458",
          "name" : "http://support.gefanuc.com/support/index?page=kbchannel&id=KB12458",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/308556",
          "name" : "VU#308556",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487076/100/0/threaded",
          "name" : "20080125 C4 Security Advisory - GE Fanuc Cimplicity 6.1 Heap Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487241/100/0/threaded",
          "name" : "20080129 Re: C4 Security Advisory - GE Fanuc Cimplicity 6.1 Heap Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27447",
          "name" : "27447",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019275",
          "name" : "1019275",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0306",
          "name" : "ADV-2008-0306",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in w32rtr.exe in GE Fanuc CIMPLICITY HMI SCADA system 7.0 before 7.0 SIM 9, and earlier versions before 6.1 SP6 Hot fix - 010708_162517_6106, allow remote attackers to execute arbitrary code via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ge_fanuc:cimplicity:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.1_sp6_hf_010708_162517_6106"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ge_fanuc:cimplicity:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.0_sim8"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T02:00Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0177",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kame",
            "product" : {
              "product_data" : [ {
                "product_name" : "ipcomp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/netinet6/ipcomp_input.c?f=u&only_with_tag=netbsd-3-1",
          "name" : "http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/netinet6/ipcomp_input.c?f=u&only_with_tag=netbsd-3-1",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html",
          "name" : "APPLE-SA-2008-07-11",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008//May/msg00001.html",
          "name" : "APPLE-SA-2008-05-28",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28788",
          "name" : "28788",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28816",
          "name" : "28816",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28979",
          "name" : "28979",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29130",
          "name" : "29130",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30430",
          "name" : "30430",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31074",
          "name" : "31074",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.freebsd.org/advisories/FreeBSD-SA-08:04.ipsec.asc",
          "name" : "FreeBSD-SA-08:04",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019314",
          "name" : "1019314",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kame.net/dev/cvsweb2.cgi/kame/kame/sys/netinet6/ipcomp_input.c.diff?r1=1.36;r2=1.37",
          "name" : "http://www.kame.net/dev/cvsweb2.cgi/kame/kame/sys/netinet6/ipcomp_input.c.diff?r1=1.36;r2=1.37",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/110947",
          "name" : "VU#110947",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27642",
          "name" : "27642",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-150A.html",
          "name" : "TA08-150A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0441",
          "name" : "ADV-2008-0441",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0688",
          "name" : "ADV-2008-0688",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1697",
          "name" : "ADV-2008-1697",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2094/references",
          "name" : "ADV-2008-2094",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5191",
          "name" : "5191",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kame:ipcomp:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0178",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "liferay",
            "product" : {
              "product_data" : [ {
                "product_name" : "liferay_enterprise_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28742",
          "name" : "28742",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://support.liferay.com/browse/LEP-4736",
          "name" : "http://support.liferay.com/browse/LEP-4736",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/326065",
          "name" : "VU#326065",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27547",
          "name" : "27547",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Enterprise Admin Session Monitoring component in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the User-Agent HTTP header."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:4.3.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-05T00:00Z",
    "lastModifiedDate" : "2008-09-05T21:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0179",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "liferay",
            "product" : {
              "product_data" : [ {
                "product_name" : "liferay_enterprise_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28742",
          "name" : "28742",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.liferay.com/browse/LEP-4737",
          "name" : "http://support.liferay.com/browse/LEP-4737",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/888209",
          "name" : "VU#888209",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27550",
          "name" : "27550",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header, which is used when composing Forgot Password e-mail messages in HTML format."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:4.3.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-05T00:00Z",
    "lastModifiedDate" : "2008-09-05T21:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0180",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "liferay",
            "product" : {
              "product_data" : [ {
                "product_name" : "liferay_enterprise_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28742",
          "name" : "28742",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://support.liferay.com/browse/LEP-4738",
          "name" : "http://support.liferay.com/browse/LEP-4738",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/732449",
          "name" : "VU#732449",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27546",
          "name" : "27546",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in themes/_unstyled/templates/init.vm in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Greeting field in a User Profile."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:3.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:4.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:4.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:4.3.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-05T00:00Z",
    "lastModifiedDate" : "2008-09-05T21:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0181",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "liferay",
            "product" : {
              "product_data" : [ {
                "product_name" : "liferay_enterprise_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28742",
          "name" : "28742",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://support.liferay.com/browse/LEP-4739",
          "name" : "http://support.liferay.com/browse/LEP-4739",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/217825",
          "name" : "VU#217825",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27554",
          "name" : "27554",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Admin portlet in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Shutdown message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:4.3.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-05T00:00Z",
    "lastModifiedDate" : "2008-09-05T21:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0182",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "liferay",
            "product" : {
              "product_data" : [ {
                "product_name" : "liferay_enterprise_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28742",
          "name" : "28742",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://support.liferay.com/browse/LEP-4739",
          "name" : "http://support.liferay.com/browse/LEP-4739",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/767825",
          "name" : "VU#767825",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-05T00:00Z",
    "lastModifiedDate" : "2008-09-05T21:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0184",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "prenotazioni_on_line",
            "product" : {
              "product_data" : [ {
                "product_name" : "syshotel_on_line_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3528",
          "name" : "3528",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485940/100/0/threaded",
          "name" : "20080108 sysHotel On Line Remote File Disclosure Vulnerability.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27184",
          "name" : "27184",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary files via an encoded \"/\" (\"%2F\") in the file parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:prenotazioni_on_line:syshotel_on_line_system:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-09T22:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0185",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "netrisk",
            "product" : {
              "product_data" : [ {
                "product_name" : "netrisk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28328",
          "name" : "28328",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=551208&group_id=129681",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=551208&group_id=129681",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485834/100/0/threaded",
          "name" : "20080106 netrisk 1.9.7 Multiple Remote Vulnerabilities (sql injection/xss)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27161",
          "name" : "27161",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4852",
          "name" : "4852",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the pid parameter in a profile page (possibly profile.php)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netrisk:netrisk:1.9.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-09T22:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0186",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phprisk",
            "product" : {
              "product_data" : [ {
                "product_name" : "netrisk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28369",
          "name" : "28369",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485834/100/0/threaded",
          "name" : "20080106 netrisk 1.9.7 Multiple Remote Vulnerabilities (sql injection/xss)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27161",
          "name" : "27161",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4852",
          "name" : "4852",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in NetRisk 1.9.7 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to CVE-2008-0144."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phprisk:netrisk:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.9.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-09T22:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0187",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "spacial_audio_solutions",
            "product" : {
              "product_data" : [ {
                "product_name" : "samphpweb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27147",
          "name" : "27147",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39463",
          "name" : "sambroadcaster-songinfo-sql-injection(39463)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4836",
          "name" : "4836",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spacial_audio_solutions:samphpweb:4.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-09T22:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0188",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its requester.  Further investigation showed that it was not a new security issue.  Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2008-01-17T00:00Z",
    "lastModifiedDate" : "2008-09-11T01:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0189",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its requester.  Further investigation showed that it was not a new security issue.  Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2008-01-17T00:00Z",
    "lastModifiedDate" : "2008-09-11T01:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0190",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "awesometemplateengine",
            "product" : {
              "product_data" : [ {
                "product_name" : "awesometemplateengine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument784.html",
          "name" : "http://securityvulns.ru/Sdocument784.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://websecurity.com.ua/1694/",
          "name" : "http://websecurity.com.ua/1694/",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27125",
          "name" : "27125",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39396",
          "name" : "awesometemplateengine-multiple-xss(39396)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in templates/example_template.php in AwesomeTemplateEngine allow remote attackers to inject arbitrary web script or HTML via the (1) data[title], (2) data[message], (3) data[table][1][item], (4) data[table][1][url], or (5) data[poweredby] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:awesometemplateengine:awesometemplateengine:1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0191",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument663.html",
          "name" : "http://securityvulns.ru/Sdocument663.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1634/",
          "name" : "http://websecurity.com.ua/1634/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39423",
          "name" : "wordpress-p-path-disclosure(39423)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0192",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument714.html",
          "name" : "http://securityvulns.ru/Sdocument714.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://websecurity.com.ua/1658/",
          "name" : "http://websecurity.com.ua/1658/",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27123",
          "name" : "27123",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39426",
          "name" : "wordpress-popuptitle-xss(39426)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the popuptitle parameter to (1) wp-admin/post.php or (2) wp-admin/page-new.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0193",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.11",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2_revision5002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2_revision5003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/29014",
          "name" : "29014",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument755.html",
          "name" : "http://securityvulns.ru/Sdocument755.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://websecurity.com.ua/1676/",
          "name" : "http://websecurity.com.ua/1676/",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1502",
          "name" : "DSA-1502",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27123",
          "name" : "27123",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to wp-admin/edit.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.11"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.1.3_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.1.3_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.2_revision5002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.2_revision5003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0194",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/29014",
          "name" : "29014",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument755.html",
          "name" : "http://securityvulns.ru/Sdocument755.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1676/",
          "name" : "http://websecurity.com.ua/1676/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1502",
          "name" : "DSA-1502",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27123",
          "name" : "27123",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.  NOTE: this might be the same as CVE-2006-5705.1."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0195",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument762.html",
          "name" : "http://securityvulns.ru/Sdocument762.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument768.html",
          "name" : "http://securityvulns.ru/Sdocument768.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument772.html",
          "name" : "http://securityvulns.ru/Sdocument772.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument773.html",
          "name" : "http://securityvulns.ru/Sdocument773.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1679/",
          "name" : "http://websecurity.com.ua/1679/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1683/",
          "name" : "http://websecurity.com.ua/1683/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1686/",
          "name" : "http://websecurity.com.ua/1686/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1687/",
          "name" : "http://websecurity.com.ua/1687/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals the path in various error messages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0196",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument762.html",
          "name" : "http://securityvulns.ru/Sdocument762.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument768.html",
          "name" : "http://securityvulns.ru/Sdocument768.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument772.html",
          "name" : "http://securityvulns.ru/Sdocument772.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument773.html",
          "name" : "http://securityvulns.ru/Sdocument773.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1679/",
          "name" : "http://websecurity.com.ua/1679/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1683/",
          "name" : "http://websecurity.com.ua/1683/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1686/",
          "name" : "http://websecurity.com.ua/1686/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1687/",
          "name" : "http://websecurity.com.ua/1687/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in WordPress 2.0.11 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the page parameter to certain PHP scripts under wp-admin/ or (2) the import parameter to wp-admin/admin.php, as demonstrated by discovering the full path via a request for the \\..\\..\\wp-config pathname; and allow remote attackers to modify arbitrary files via a .. (dot dot) in the file parameter to wp-admin/templates.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0197",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wp-contactform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5_alpha",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument546.html",
          "name" : "http://securityvulns.ru/Sdocument546.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument667.html",
          "name" : "http://securityvulns.ru/Sdocument667.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1600/",
          "name" : "http://websecurity.com.ua/1600/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1641/",
          "name" : "http://websecurity.com.ua/1641/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) wpcf_email, (2) wpcf_subject, (3) wpcf_question, (4) wpcf_answer, (5) wpcf_success_msg, (6) wpcf_error_msg, or (7) wpcf_msg parameter to wp-admin/admin.php, or (8) the SRC attribute of an IFRAME element."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wp-contactform:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5_alpha"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0198",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument546.html",
          "name" : "http://securityvulns.ru/Sdocument546.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument667.html",
          "name" : "http://securityvulns.ru/Sdocument667.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1600/",
          "name" : "http://websecurity.com.ua/1600/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1641/",
          "name" : "http://websecurity.com.ua/1641/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site request forgery (CSRF) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) wpcf_question, (2) wpcf_success_msg, or (3) wpcf_error_msg parameter to wp-admin/admin.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0199",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pro_search",
            "product" : {
              "product_data" : [ {
                "product_name" : "pro_search",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.16",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument731.html",
          "name" : "http://securityvulns.ru/Sdocument731.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=563784&group_id=149797",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=563784&group_id=149797",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1259/",
          "name" : "http://websecurity.com.ua/1259/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PRO-Search 0.17 and earlier allows remote attackers to cause a denial of service via certain values of the show_page and time parameters to the default URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pro_search:pro_search:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.16"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0200",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "medialand",
            "product" : {
              "product_data" : [ {
                "product_name" : "rotabanner_local",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument625.html",
          "name" : "http://securityvulns.ru/Sdocument625.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1442/",
          "name" : "http://websecurity.com.ua/1442/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27138",
          "name" : "27138",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in account/index.html in RotaBanner Local 3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) drop parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:medialand:rotabanner_local:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0201",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "expressionengine",
            "product" : {
              "product_data" : [ {
                "product_name" : "expressionengine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument472.html",
          "name" : "http://securityvulns.ru/Sdocument472.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1454/",
          "name" : "http://websecurity.com.ua/1454/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27128",
          "name" : "27128",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39442",
          "name" : "expressionengine-index-xss(39442)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:expressionengine:expressionengine:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0202",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "expressionengine",
            "product" : {
              "product_data" : [ {
                "product_name" : "expressionengine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument472.html",
          "name" : "http://securityvulns.ru/Sdocument472.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1454/",
          "name" : "http://websecurity.com.ua/1454/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27128",
          "name" : "27128",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CRLF injection vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:expressionengine:expressionengine:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0203",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "cryptographp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1596/",
          "name" : "http://websecurity.com.ua/1596/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in cryptographp/admin.php in the Cryptographp 1.2 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cryptwidth, (2) cryptheight, (3) bgimg, (4) charR, (5) charG, (6) charB, (7) charclear, (8) tfont, (9) charel, (10) charelc, (11) charelv, (12) charnbmin, (13) charnbmax, (14) charspace, (15) charsizemin, (16) charsizemax, (17) charanglemax, (18) noisepxmin, (19) noisepxmax, (20) noiselinemin, (21) noiselinemax, (22) nbcirclemin, (23) nbcirclemax, or (24) brushsize parameter to wp-admin/options-general.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:cryptographp:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0204",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "math_comment_spam_protection_plugin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1576/",
          "name" : "http://websecurity.com.ua/1576/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to wp-admin/options-general.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:math_comment_spam_protection_plugin:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0205",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "math_comment_spam_protection_plugin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1576/",
          "name" : "http://websecurity.com.ua/1576/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site request forgery (CSRF) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to wp-admin/options-general.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:math_comment_spam_protection_plugin:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0206",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "captcha",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5d",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1588/",
          "name" : "http://websecurity.com.ua/1588/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in captcha\\captcha.php in the Captcha! 2.5d and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) captcha_ttffolder, (2) captcha_numchars, (3) captcha_ttfrange, or (4) captcha_secret parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:captcha:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.5d"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0207",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pro_search",
            "product" : {
              "product_data" : [ {
                "product_name" : "pro_search",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.17",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28335",
          "name" : "28335",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3539",
          "name" : "3539",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.ru/Sdocument731.html",
          "name" : "http://securityvulns.ru/Sdocument731.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=563784&group_id=149797",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=563784&group_id=149797",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://websecurity.com.ua/1259/",
          "name" : "http://websecurity.com.ua/1259/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485786/100/0/threaded",
          "name" : "20080103 securityvulns.com russian vulnerabilities digest",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27126",
          "name" : "27126",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in PRO-Search 0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prot, (2) host, (3) path, (4) name, (5) ext, (6) size, (7) search_days, or (8) show_page parameter to the default URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pro_search:pro_search:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.17"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0208",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "snitz_communications",
            "product" : {
              "product_data" : [ {
                "product_name" : "snitz_forums_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.05",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://hackerscenter.com/archive/view.asp?id=28145",
          "name" : "http://hackerscenter.com/archive/view.asp?id=28145",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28284",
          "name" : "28284",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt",
          "name" : "http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485836/100/200/threaded",
          "name" : "20080107 [HSC] Snitz Forums Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27162",
          "name" : "27162",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in login.asp in Snitz Forums 2000 3.4.05 and earlier allows remote attackers to inject arbitrary web script or HTML via the target parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.1:sr4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.2.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.4.05"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0209",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "snitz_communications",
            "product" : {
              "product_data" : [ {
                "product_name" : "snitz_forums_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.06",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://hackerscenter.com/archive/view.asp?id=28145",
          "name" : "http://hackerscenter.com/archive/view.asp?id=28145",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt",
          "name" : "http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485836/100/200/threaded",
          "name" : "20080107 [HSC] Snitz Forums Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Open redirect vulnerability in Forums/login.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to redirect users to arbitrary web sites via a URL in the target parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.1:sr4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.2.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.05:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snitz_communications:snitz_forums_2000:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.4.06"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0210",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "uebimiau",
            "product" : {
              "product_data" : [ {
                "product_name" : "webmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27154",
          "name" : "27154",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4846",
          "name" : "4846",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting.  NOTE: this can be leveraged to conduct directory traversal attacks without authentication by using CVE-2008-0140."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uebimiau:webmail:2.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uebimiau:webmail:2.7.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T00:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0211",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "compaq",
            "product" : {
              "product_data" : [ {
                "product_name" : "2210_series_bios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "f.04",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "2510_series_bios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "f.08",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "2710_series_bios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "f.0d",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "6510_series_bios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "f.0f",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "6515_series_bios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "f.0a",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "6520_series_bios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "f.08",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "6710_series_bios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "f.0f",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "6715_series_bios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "f.0a",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "6720_series_bios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "f.08",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "6820_series_bios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "f.08",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "6910_series_bios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "f.11",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "8510_series_bios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "f.0e",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "8710_series_bios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "f.08",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120672155821700&w=2",
          "name" : "SSRT080004",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019729",
          "name" : "1019729",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28494",
          "name" : "28494",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1042/references",
          "name" : "ADV-2008-1042",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41520",
          "name" : "compaq-businessnotebook-pcbios-dos(41520)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the BIOS F.04 through F.11 for the HP Compaq Business Notebook PC allows local users to cause a denial of service via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compaq:2210_series_bios:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "f.04"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compaq:2510_series_bios:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "f.08"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compaq:2710_series_bios:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "f.0d"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compaq:6510_series_bios:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "f.0f"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compaq:6515_series_bios:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "f.0a"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compaq:6520_series_bios:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "f.08"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compaq:6710_series_bios:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "f.0f"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compaq:6715_series_bios:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "f.0a"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compaq:6720_series_bios:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "f.08"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compaq:6820_series_bios:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "f.08"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compaq:6910_series_bios:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "f.11"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compaq:8510_series_bios:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "f.0e"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compaq:8710_series_bios:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "f.08"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-31T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0212",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "openview_network_node_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.51",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=652",
          "name" : "20080204 Hewlett-Packard Network Node Manager Topology Manager Service DoS Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28798",
          "name" : "28798",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487586/100/0/threaded",
          "name" : "HPSBMA02307",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27629",
          "name" : "27629",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019306",
          "name" : "1019306",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0424",
          "name" : "ADV-2008-0424",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ovtopmd in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to cause a denial of service (crash) via a crafted TCP request that triggers an out-of-bounds memory access."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.23:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:sun:solaris:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:6.41:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.01:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.51:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T21:00Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0213",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "virtual_rooms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120231595903371&w=2",
          "name" : "SSRT080007",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019311",
          "name" : "1019311",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in a certain ActiveX control for HP Virtual Rooms (HPVR) 6 and earlier allows remote attackers to execute arbitrary code via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:virtual_rooms:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T22:00Z",
    "lastModifiedDate" : "2019-10-09T22:54Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0214",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "select_identity",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.20",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120239931201443&w=2",
          "name" : "HPSBMA02309",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28844",
          "name" : "28844",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27667",
          "name" : "27667",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019322",
          "name" : "1019322",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0472",
          "name" : "ADV-2008-0472",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to gain access via unknown vectors."
        }, {
          "lang" : "en",
          "value" : "In order to download the patch, user must login."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:select_identity:4.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:select_identity:4.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:select_identity:4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:select_identity:4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:select_identity:4.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:select_identity:4.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:select_identity:4.20:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-08T02:00Z",
    "lastModifiedDate" : "2011-03-08T03:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0215",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "storage_essentials_srm_enterprise",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.3",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "storage_essentials_srm_standard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          }, {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01316132",
          "name" : "SSRT071474",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28813",
          "name" : "28813",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27643",
          "name" : "27643",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019312",
          "name" : "1019312",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0440",
          "name" : "ADV-2008-0440",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in HP Storage Essentials Storage Resource Management (SRM) before 6.0.0 allow remote attackers to obtain unspecified access to a managed device via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:storage_essentials_srm_enterprise:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:storage_essentials_srm_standard:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T02:00Z",
    "lastModifiedDate" : "2011-03-08T03:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0216",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28498",
          "name" : "28498",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc",
          "name" : "FreeBSD-SA-08:01",
          "refsource" : "FREEBSD",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27284",
          "name" : "27284",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019191",
          "name" : "1019191",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39667",
          "name" : "freebsd-ptsname-information-disclosure(39667)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:stable:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.1:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.1:release_p10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.1:stable:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:stable:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:7.0:current:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:7.0:pre-release:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T02:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0217",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28498",
          "name" : "28498",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc",
          "name" : "FreeBSD-SA-08:01",
          "refsource" : "FREEBSD",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27284",
          "name" : "27284",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019191",
          "name" : "1019191",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39665",
          "name" : "freebsd-openpty-information-disclosure(39665)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:7.0:pre-release:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T02:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0218",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "merak",
            "product" : {
              "product_data" : [ {
                "product_name" : "icewarp_mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28460",
          "name" : "28460",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27189",
          "name" : "27189",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/data/vulnerabilities/exploits/27189.html",
          "name" : "http://www.securityfocus.com/data/vulnerabilities/exploits/27189.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0135",
          "name" : "ADV-2008-0135",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39564",
          "name" : "icewarpmailserver-index-xss(39564)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inject arbitrary web script or HTML via the message parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:merak:icewarp_mail_server:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T23:46Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0219",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php_webquest",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_webquest",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/26821",
          "name" : "26821",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27192",
          "name" : "27192",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39560",
          "name" : "webquest-soportehorizontalw-sql-injection(39560)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4867",
          "name" : "4867",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in soporte_horizontal_w.php in PHP Webquest 2.6 allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter, a different vector than CVE-2007-4920."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_webquest:php_webquest:2.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T23:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0220",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gateway",
            "product" : {
              "product_data" : [ {
                "product_name" : "cweblaunchctl_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "weblaunch",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=119984138526735&w=2",
          "name" : "20080109 Gateway WebLaunch ActiveX Control Insecure Method",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28379",
          "name" : "28379",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/735441",
          "name" : "VU#735441",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27193",
          "name" : "27193",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0077",
          "name" : "ADV-2008-0077",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4869",
          "name" : "4869",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4982",
          "name" : "4982",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary code via a long string in the (1) second or (2) fourth argument to the DoWebLaunch method.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gateway:cweblaunchctl_activex_control:1.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gateway:weblaunch:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T23:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0221",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gateway",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblaunch",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=119984138526735&w=2",
          "name" : "20080109 Gateway WebLaunch ActiveX Control Insecure Method",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28379",
          "name" : "28379",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0077",
          "name" : "ADV-2008-0077",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4869",
          "name" : "4869",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allows remote attackers to execute arbitrary programs via a ..\\ (dot dot backslash) in the second argument to the DoWebLaunch method.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gateway:weblaunch:1.0.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T23:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0222",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "filemanager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27151",
          "name" : "27151",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39462",
          "name" : "wordpress-wpfilemanager-file-upload(39462)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4844",
          "name" : "4844",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:filemanager:1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T23:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0223",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "justsystem",
            "product" : {
              "product_data" : [ {
                "product_name" : "ichitaro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "13.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "linux",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ichitaro_lite2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ichitaro_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jvn.jp/jp/JVN%2308237857/index.html",
          "name" : "JVN#08237857",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28275",
          "name" : "28275",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20080107",
          "name" : "http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20080107",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.justsystems.com/jp/info/pd8001.html",
          "name" : "http://www.justsystems.com/jp/info/pd8001.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27153",
          "name" : "27153",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019168",
          "name" : "1019168",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0045",
          "name" : "ADV-2008-0045",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39501",
          "name" : "justsystems-jsfc-bo(39501)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in JustSystems JSFC.DLL, as used in multiple JustSystems products such as Ichitaro, allows remote attackers to execute arbitrary code via a crafted .JTD file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:justsystem:ichitaro:11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:justsystem:ichitaro:12.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:justsystem:ichitaro:13.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:justsystem:ichitaro:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:justsystem:ichitaro:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:justsystem:ichitaro:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:justsystem:ichitaro:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:justsystem:ichitaro:linux:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:justsystem:ichitaro_lite2:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:justsystem:ichitaro_viewer:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T23:46Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0224",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "runcms",
            "product" : {
              "product_data" : [ {
                "product_name" : "runcms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28340",
          "name" : "28340",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27152",
          "name" : "27152",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39478",
          "name" : "runcms-newbb-client-sql-injection(39478)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4845",
          "name" : "4845",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrary SQL commands via the Client-Ip parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:runcms:1.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:runcms:1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:runcms:1.6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T23:46Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0225",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xine",
            "product" : {
              "product_data" : [ {
                "product_name" : "xine-lib",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/xinermffhof-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/xinermffhof-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=205197",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=205197",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28384",
          "name" : "28384",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28489",
          "name" : "28489",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28507",
          "name" : "28507",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28636",
          "name" : "28636",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28674",
          "name" : "28674",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28955",
          "name" : "28955",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31393",
          "name" : "31393",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200801-12.xml",
          "name" : "GLSA-200801-12",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=567872",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=567872",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1472",
          "name" : "DSA-1472",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:020",
          "name" : "MDVSA-2008:020",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:045",
          "name" : "MDVSA-2008:045",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/suse_security_summary_report.html",
          "name" : "SUSE-SR:2008:002",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27198",
          "name" : "27198",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-635-1",
          "name" : "USN-635-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0163",
          "name" : "ADV-2008-0163",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=428620",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=428620",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00592.html",
          "name" : "FEDORA-2008-0718",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute in an RTSP session, related to the rmff_dump_header function and related to disregarding the max field.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xine:xine-lib:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T23:46Z",
    "lastModifiedDate" : "2011-10-17T04:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0226",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mysql",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.56",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.66",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.56",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.58",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.66",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.22",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "yassl",
            "product" : {
              "product_data" : [ {
                "product_name" : "yassl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.mysql.com/33814",
          "name" : "http://bugs.mysql.com/33814",
          "refsource" : "CONFIRM",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html",
          "name" : "http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Not Applicable" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html",
          "name" : "APPLE-SA-2008-10-09",
          "refsource" : "APPLE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28324",
          "name" : "28324",
          "refsource" : "SECUNIA",
          "tags" : [ "Not Applicable" ]
        }, {
          "url" : "http://secunia.com/advisories/28419",
          "name" : "28419",
          "refsource" : "SECUNIA",
          "tags" : [ "Not Applicable" ]
        }, {
          "url" : "http://secunia.com/advisories/28597",
          "name" : "28597",
          "refsource" : "SECUNIA",
          "tags" : [ "Not Applicable" ]
        }, {
          "url" : "http://secunia.com/advisories/29443",
          "name" : "29443",
          "refsource" : "SECUNIA",
          "tags" : [ "Not Applicable" ]
        }, {
          "url" : "http://secunia.com/advisories/32222",
          "name" : "32222",
          "refsource" : "SECUNIA",
          "tags" : [ "Not Applicable" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3531",
          "name" : "3531",
          "refsource" : "SREASON",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://support.apple.com/kb/HT3216",
          "name" : "http://support.apple.com/kb/HT3216",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1478",
          "name" : "DSA-1478",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:150",
          "name" : "MDVSA-2008:150",
          "refsource" : "MANDRIVA",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485810/100/0/threaded",
          "name" : "20080104 Multiple vulnerabilities in yaSSL 1.7.5",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485811/100/0/threaded",
          "name" : "20080104 Pre-auth buffer-overflow in mySQL through yaSSL",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27140",
          "name" : "27140",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/31681",
          "name" : "31681",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-588-1",
          "name" : "USN-588-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0560/references",
          "name" : "ADV-2008-0560",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2780",
          "name" : "ADV-2008-2780",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39429",
          "name" : "yassl-processoldclienthello-bo(39429)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39431",
          "name" : "yassl-inputbufferoperator-bo(39431)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) \"input_buffer& operator>>\" in yassl_imp.cpp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yassl:yassl:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.7.5"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.44:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.56:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.66:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.30:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.36:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.38:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.44:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.45:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.46:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.50:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.56:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.58:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.60:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.64:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.66:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.1.22:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.4:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T23:46Z",
    "lastModifiedDate" : "2019-12-17T20:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0227",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "yassl",
            "product" : {
              "product_data" : [ {
                "product_name" : "yassl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.mysql.com/33814",
          "name" : "http://bugs.mysql.com/33814",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html",
          "name" : "http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html",
          "name" : "APPLE-SA-2008-10-09",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28324",
          "name" : "28324",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28597",
          "name" : "28597",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29443",
          "name" : "29443",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32222",
          "name" : "32222",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3531",
          "name" : "3531",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT3216",
          "name" : "http://support.apple.com/kb/HT3216",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1478",
          "name" : "DSA-1478",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:150",
          "name" : "MDVSA-2008:150",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485810/100/0/threaded",
          "name" : "20080104 Multiple vulnerabilities in yaSSL 1.7.5",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27140",
          "name" : "27140",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/31681",
          "name" : "31681",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-588-1",
          "name" : "USN-588-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0560/references",
          "name" : "ADV-2008-0560",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2780",
          "name" : "ADV-2008-2780",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39433",
          "name" : "yassl-hashwithtransformupdate-dos(39433)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yassl:yassl:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.7.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T23:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0228",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linksys",
            "product" : {
              "product_data" : [ {
                "product_name" : "wrt54gl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.30.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28364",
          "name" : "28364",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3534",
          "name" : "3534",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485853/100/0/threaded",
          "name" : "20080107 Linksys WRT54 GL - Session riding (CSRF)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486362/100/0/threaded",
          "name" : "20080115 Re: Linksys WRT54 GL - Session riding (CSRF)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39502",
          "name" : "linksys-apply-csrf(39502)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote attackers to perform actions as administrators."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:linksys:wrt54gl:4.30.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-10T23:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0229",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "level_one",
            "product" : {
              "product_data" : [ {
                "product_name" : "wbr-3460a",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28397",
          "name" : "28397",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3533",
          "name" : "3533",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485935/100/0/threaded",
          "name" : "20080108 Level-One WBR-3460A Grants Root Access",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27183",
          "name" : "27183",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019162",
          "name" : "1019162",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The telnet service in LevelOne WBR-3460 4-Port ADSL 2/2+ Wireless Modem Router with firmware 1.00.11 and 1.00.12 does not require authentication, which allows remote attackers on the local or wireless network to obtain administrative access."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:level_one:wbr-3460a:1.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:level_one:wbr-3460a:1.0.12:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-10T23:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0230",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "osdate",
            "product" : {
              "product_data" : [ {
                "product_name" : "osdate",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.org/0801-exploits/osdata-lfi.txt",
          "name" : "http://packetstormsecurity.org/0801-exploits/osdata-lfi.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28420",
          "name" : "28420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27208",
          "name" : "27208",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39567",
          "name" : "osdate-php121db-file-include(39567)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4870",
          "name" : "4870",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via a URL in the php121dir parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:osdate:osdate:2.0.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-11T00:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0231",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tuned_studios",
            "product" : {
              "product_data" : [ {
                "product_name" : "classic_theme",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "endless",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "freeze_theme",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "lonely_maple",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "music_theme",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "orange_cutout",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "subwoofer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3532",
          "name" : "3532",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485991/100/0/threaded",
          "name" : "20080109 LFI in Tuned Studios Templates",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27196",
          "name" : "27196",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39555",
          "name" : "tunedstudiostemplates-index-file-include(39555)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4876",
          "name" : "4876",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange Cutout, (4) Lonely Maple, (5) Endless, (6) Classic Theme, and (7) Music Theme webpage templates allow remote attackers to include and execute arbitrary files via \"..\" sequences in the page parameter.  NOTE: this can be leveraged for remote file inclusion when running in some PHP 5 environments."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tuned_studios:classic_theme:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tuned_studios:endless:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tuned_studios:freeze_theme:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tuned_studios:lonely_maple:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tuned_studios:music_theme:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tuned_studios:orange_cutout:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tuned_studios:subwoofer:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-11T00:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0232",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zero_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "zero_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0_alpha",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.org/0801-exploits/zerocms-sql.txt",
          "name" : "http://packetstormsecurity.org/0801-exploits/zerocms-sql.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27186",
          "name" : "27186",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39530",
          "name" : "zerocms-index-sql-injection(39530)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4864",
          "name" : "4864",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to index.php, or the (2) f or t parameters to forums/index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zero_cms:zero_cms:1.0_alpha:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-11T00:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0233",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zero_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "zero_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0_alpha",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.org/0801-exploits/zerocms-sql.txt",
          "name" : "http://packetstormsecurity.org/0801-exploits/zerocms-sql.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4864",
          "name" : "4864",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zero_cms:zero_cms:1.0_alpha:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-11T02:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0234",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.3.1.70",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//Jul/msg00000.html",
          "name" : "APPLE-SA-2008-07-10",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Feb/msg00001.html",
          "name" : "APPLE-SA-2008-02-06",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28423",
          "name" : "28423",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31034",
          "name" : "31034",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3537",
          "name" : "3537",
          "refsource" : "SREASON",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/112179",
          "name" : "VU#112179",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486091/100/0/threaded",
          "name" : "20080110 Buffer-overflow in Quicktime Player 7.3.1.70",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486114/100/0/threaded",
          "name" : "20080110 Re: Buffer-overflow in Quicktime Player 7.3.1.70",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486161/100/0/threaded",
          "name" : "20080111 Re: Re: Buffer-overflow in Quicktime Player 7.3.1.70",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486174/100/0/threaded",
          "name" : "20080111 Re: Buffer-overflow in Quicktime Player 7.3.1.70",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486238/100/0/threaded",
          "name" : "20080114 Re: [Full-disclosure] Buffer-overflow in Quicktime Player 7.3.1.70",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486241/100/0/threaded",
          "name" : "20080112 Re: Re: Buffer-overflow in Quicktime Player 7.3.1.70",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486268/100/0/threaded",
          "name" : "20080112 Re: Buffer-overflow in Quicktime Player 7.3.1.70",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27225",
          "name" : "27225",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019178",
          "name" : "1019178",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0107",
          "name" : "ADV-2008-0107",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2064/references",
          "name" : "ADV-2008-2064",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39601",
          "name" : "quicktime-rtsp-responses-bo(39601)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4885",
          "name" : "4885",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4906",
          "name" : "4906",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.3.1.70:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-11T02:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0235",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "vfp_ole_server_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.org/0801-exploits/msvfpole-exec.txt",
          "name" : "http://packetstormsecurity.org/0801-exploits/msvfpole-exec.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28417",
          "name" : "28417",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://shinnai.altervista.org/exploits/txt/TXT_rNowA1916DKFNUF48NyS.html",
          "name" : "http://shinnai.altervista.org/exploits/txt/TXT_rNowA1916DKFNUF48NyS.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27199",
          "name" : "27199",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39559",
          "name" : "microsoft-vfpoleserver-command-execution(39559)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4875",
          "name" : "4875",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:vfp_ole_server_activex_control:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-11T02:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0236",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "visual_foxpro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28417",
          "name" : "28417",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://shinnai.altervista.org/exploits/txt/TXT_DiWu9j82RCq4zpaQAoxn.html",
          "name" : "http://shinnai.altervista.org/exploits/txt/TXT_DiWu9j82RCq4zpaQAoxn.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27205",
          "name" : "27205",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39558",
          "name" : "microsoft-foxserver-command-execution(39558)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4873",
          "name" : "4873",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary commands by invoking the DoCmd method."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visual_foxpro:6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-11T02:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0237",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "rich_textbox_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://shinnai.altervista.org/exploits/txt/TXT_DZVN8CwCha0I2fI3NeEs.html",
          "name" : "http://shinnai.altervista.org/exploits/txt/TXT_DZVN8CwCha0I2fI3NeEs.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27201",
          "name" : "27201",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39557",
          "name" : "microsoft-richtextbox-file-overwrite(39557)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4874",
          "name" : "4874",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure SaveFile method."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:rich_textbox_control:6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-11T02:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0238",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xine",
            "product" : {
              "product_data" : [ {
                "product_name" : "xine-lib",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=205197",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=205197",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28384",
          "name" : "28384",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28674",
          "name" : "28674",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28955",
          "name" : "28955",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31393",
          "name" : "31393",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200801-12.xml",
          "name" : "GLSA-200801-12",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:020",
          "name" : "MDVSA-2008:020",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:045",
          "name" : "MDVSA-2008:045",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-635-1",
          "name" : "USN-635-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related to the rmff_dump_header function, different vectors than CVE-2008-0225.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        }, {
          "lang" : "en",
          "value" : "Please see the following link for more information regarding the exploit:\r\n\r\nhttp://aluigi.altervista.org/adv/xinermffhof-adv.txt"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xine:xine-lib:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-11T21:46Z",
    "lastModifiedDate" : "2008-09-11T01:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0239",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "java_system_identity_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28356",
          "name" : "28356",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3535",
          "name" : "3535",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-103180-1",
          "name" : "103180",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-66-200558-1",
          "name" : "200558",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.procheckup.com/Vulnerability_PR07-06.php",
          "name" : "http://www.procheckup.com/Vulnerability_PR07-06.php",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.procheckup.com/Vulnerability_PR07-07.php",
          "name" : "http://www.procheckup.com/Vulnerability_PR07-07.php",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.procheckup.com/Vulnerability_PR07-08.php",
          "name" : "http://www.procheckup.com/Vulnerability_PR07-08.php",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.procheckup.com/Vulnerability_PR07-09.php",
          "name" : "http://www.procheckup.com/Vulnerability_PR07-09.php",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486076/100/0/threaded",
          "name" : "20080110 PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27214",
          "name" : "27214",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019175",
          "name" : "1019175",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0089",
          "name" : "ADV-2008-0089",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39580",
          "name" : "sun-identity-login-xss(39580)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39581",
          "name" : "sun-identity-lang-xss(39581)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39582",
          "name" : "sun-identity-resultsform-xss(39582)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39583",
          "name" : "sun-identity-main-xss(39583)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to inject arbitrary HTML or web script via the (1) cntry or lang parameters to /idm/login.jsp, (2) resultsForm parameter to /idm/account/findForSelect.jsp, or (3) activeControl parameter to /idm/user/main.jsp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_identity_manager:6.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_identity_manager:6.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_identity_manager:6.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_identity_manager:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_identity_manager:7.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-11T22:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0240",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "java_system_identity_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28356",
          "name" : "28356",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3535",
          "name" : "3535",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-103180-1",
          "name" : "103180",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-66-200558-1",
          "name" : "200558",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.procheckup.com/Vulnerability_PR07-10.php",
          "name" : "http://www.procheckup.com/Vulnerability_PR07-10.php",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486076/100/0/threaded",
          "name" : "20080110 PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27214",
          "name" : "27214",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0089",
          "name" : "ADV-2008-0089",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39586",
          "name" : "sun-identity-index-frame-injection(39586)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka \"frame injection.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_identity_manager:6.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_identity_manager:6.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_identity_manager:6.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_identity_manager:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_identity_manager:7.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-11T22:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0241",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "java_system_identity_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28356",
          "name" : "28356",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3535",
          "name" : "3535",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-103180-1",
          "name" : "103180",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-66-200558-1",
          "name" : "200558",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.procheckup.com/Vulnerability_PR07-12.php",
          "name" : "http://www.procheckup.com/Vulnerability_PR07-12.php",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486076/100/0/threaded",
          "name" : "20080110 PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27214",
          "name" : "27214",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0089",
          "name" : "ADV-2008-0089",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39590",
          "name" : "sun-identity-login-security-bypass(39590)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Open redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the nextPage parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_identity_manager:6.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_identity_manager:6.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_identity_manager:6.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_identity_manager:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_identity_manager:7.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-11T22:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0242",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28493",
          "name" : "28493",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-103165-1",
          "name" : "103165",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-66-200641-1",
          "name" : "200641",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27253",
          "name" : "27253",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019187",
          "name" : "1019187",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0131",
          "name" : "ADV-2008-0131",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39629",
          "name" : "solaris-libdevinfo-privilege-escalation(39629)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5211",
          "name" : "oval:org.mitre.oval:def:5211",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in libdevinfo in Sun Solaris 10 allows local users to access files and gain privileges via unknown vectors, related to login device permissions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:x86:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-12T02:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0243",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_domino",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28411",
          "name" : "28411",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27215",
          "name" : "27215",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0086",
          "name" : "ADV-2008-0086",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg27011539",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg27011539",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39588",
          "name" : "lotus-domino-unspecified-dos(39588)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Lotus Domino 7.0.2 before Fix Pack 3 allows attackers to cause a denial of service via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:7.0.2:*:fp1:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:7.0.2:*:fp2:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-12T02:46Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0244",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sap",
            "product" : {
              "product_data" : [ {
                "product_name" : "maxdb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.6.3_build_007",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/sapone-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/sapone-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28409",
          "name" : "28409",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3536",
          "name" : "3536",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486039/100/0/threaded",
          "name" : "20080109 Pre-auth remote commands execution in SAP MaxDB 7.6.03.07",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27206",
          "name" : "27206",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019171",
          "name" : "1019171",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0104",
          "name" : "ADV-2008-0104",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39573",
          "name" : "maxdb-system-command-execution(39573)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4877",
          "name" : "4877",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via \"&&\" and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sap:maxdb:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.6.3_build_007"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-12T02:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0245",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "uploadscript",
            "product" : {
              "product_data" : [ {
                "product_name" : "uploadimage",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "uploadscript",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27203",
          "name" : "27203",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39571",
          "name" : "uploadimage-admin-command-execution(39571)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4871",
          "name" : "4871",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uploadscript:uploadimage:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uploadscript:uploadscript:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-12T02:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0246",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "uploadscript",
            "product" : {
              "product_data" : [ {
                "product_name" : "uploadimage",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "uploadscript",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27203",
          "name" : "27203",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39570",
          "name" : "uploadscript-admin-command-execution(39570)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4871",
          "name" : "4871",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uploadscript:uploadimage:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uploadscript:uploadscript:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-12T02:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0247",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tivoli_storage_manager_express",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28440",
          "name" : "28440",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486270/100/0/threaded",
          "name" : "20080114 ZDI-08-001: IBM Tivoli Storage Manager Express Backup Server Heap Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27235",
          "name" : "27235",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019182",
          "name" : "1019182",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0106",
          "name" : "ADV-2008-0106",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-001.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-001.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg21291536",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg21291536",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39604",
          "name" : "ibm-tsmexpressserver-bo(39604)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows remote attackers to execute arbitrary code via a packet with a large length value."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_express:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-12T02:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0248",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "streamaudio",
            "product" : {
              "product_data" : [ {
                "product_name" : "chaincast_proxymanager_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059572.html",
          "name" : "20080111 StreamAudio ChainCast ProxyManager ccpm_0237.dll Buffer Overflow",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28461",
          "name" : "28461",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27247",
          "name" : "27247",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0133",
          "name" : "ADV-2008-0133",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39622",
          "name" : "streamaudio-chaincastproxymanager-bo(39622)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4894",
          "name" : "4894",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to execute arbitrary code via a long URL argument to the InternalTuneIn method."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:streamaudio:chaincast_proxymanager_activex_control:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-12T02:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0249",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpwebquest",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpwebquest",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27202",
          "name" : "27202",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39572",
          "name" : "phpwebquest-backup-information-disclosure(39572)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4872",
          "name" : "4872",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if a call to /usr/bin/mysqldump fails.  NOTE: this might only be an issue in limited environments."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpwebquest:phpwebquest:2.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-12T02:46Z",
    "lastModifiedDate" : "2017-10-11T01:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0250",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "visual_interdev",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28482",
          "name" : "28482",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://shinnai.altervista.org/exploits/txt/TXT_PoEOrFM8py30PXrDF7IY.html",
          "name" : "http://shinnai.altervista.org/exploits/txt/TXT_PoEOrFM8py30PXrDF7IY.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27250",
          "name" : "27250",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41826",
          "name" : "visualinterdev-sln-project-bo(41826)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4892",
          "name" : "4892",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with a long Project line."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visual_interdev:6.0:sp6:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-12T02:46Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0251",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "photopost",
            "product" : {
              "product_data" : [ {
                "product_name" : "photopost_vbgallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          }, {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28430",
          "name" : "28430",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.photopost.com/forum/showthread.php?t=134909",
          "name" : "http://www.photopost.com/forum/showthread.php?t=134909",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.photopost.com/forum/showthread.php?t=134910",
          "name" : "http://www.photopost.com/forum/showthread.php?t=134910",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39621",
          "name" : "vbgallery-unspecified-code-execution(39621)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:photopost:photopost_vbgallery:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.4.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-12T02:46Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0252",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cherrypy",
            "product" : {
              "product_data" : [ {
                "product_name" : "cherrypy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.0",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28353",
          "name" : "28353",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28354",
          "name" : "28354",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28611",
          "name" : "28611",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28620",
          "name" : "28620",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28769",
          "name" : "28769",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200801-11.xml",
          "name" : "GLSA-200801-11",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.cherrypy.org/changeset/1774",
          "name" : "http://www.cherrypy.org/changeset/1774",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.cherrypy.org/changeset/1775",
          "name" : "http://www.cherrypy.org/changeset/1775",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.cherrypy.org/changeset/1776",
          "name" : "http://www.cherrypy.org/changeset/1776",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.cherrypy.org/ticket/744",
          "name" : "http://www.cherrypy.org/ticket/744",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1481",
          "name" : "DSA-1481",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487001/100/0/threaded",
          "name" : "20080124 rPSA-2008-0030-1 CherryPy",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27181",
          "name" : "27181",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0039",
          "name" : "ADV-2008-0039",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugs.gentoo.org/show_bug.cgi?id=204829",
          "name" : "https://bugs.gentoo.org/show_bug.cgi?id=204829",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2127",
          "name" : "https://issues.rpath.com/browse/RPL-2127",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00240.html",
          "name" : "FEDORA-2008-0299",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00297.html",
          "name" : "FEDORA-2008-0333",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the _get_file_path function in (1) lib/sessions.py in CherryPy 3.0.x up to 3.0.2, (2) filter/sessionfilter.py in CherryPy 2.1, and (3) filter/sessionfilter.py in CherryPy 2.x allows remote attackers to create or delete arbitrary files, and possibly read and write portions of arbitrary files, via a crafted session id in a cookie."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-12T02:46Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0253",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "binn",
            "product" : {
              "product_data" : [ {
                "product_name" : "sbuilder",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/486265/100/0/threaded",
          "name" : "20080114 Binn SBuilder (nid) Remote Blind Sql Injection Vulnerabily",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27264",
          "name" : "27264",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39634",
          "name" : "binnsbuilder-fulltext-sql-injection(39634)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4904",
          "name" : "4904",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands via the nid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:binn:sbuilder:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0254",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wavelink_media",
            "product" : {
              "product_data" : [ {
                "product_name" : "tutorialcms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28446",
          "name" : "28446",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27263",
          "name" : "27263",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39642",
          "name" : "tutorialcms-activate-sql-injection(39642)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4901",
          "name" : "4901",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the userName parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wavelink_media:tutorialcms:1.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0255",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "igamingcms",
            "product" : {
              "product_data" : [ {
                "product_name" : "igaming_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28426",
          "name" : "28426",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27230",
          "name" : "27230",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39598",
          "name" : "igamingcms-archive-sql-injection(39598)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4886",
          "name" : "4886",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in archive.php in iGaming 1.5, and 1.3.1 and earlier, allows remote attackers to execute arbitrary SQL commands via the section parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:igamingcms:igaming_cms:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:igamingcms:igaming_cms:1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0256",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "matteo_binda",
            "product" : {
              "product_data" : [ {
                "product_name" : "asp_photo_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28447",
          "name" : "28447",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27262",
          "name" : "27262",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39646",
          "name" : "aspphotogallery-multiple-sql-injection(39646)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4900",
          "name" : "4900",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) Imgbig.asp, (b) thumb.asp, and (c) thumbricerca.asp and the (2) ricerca parameter to (d) thumbricerca.asp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matteo_binda:asp_photo_gallery:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0257",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dansie",
            "product" : {
              "product_data" : [ {
                "product_name" : "search_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28465",
          "name" : "28465",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27269",
          "name" : "27269",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39636",
          "name" : "dansiesearchengine-search-xss(39636)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search.pl in Dansie Search Engine 2.7 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dansie:search_engine:2.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0258",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php_running_management",
            "product" : {
              "product_data" : [ {
                "product_name" : "phprunman",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28474",
          "name" : "28474",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=568237&group_id=103505",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=568237&group_id=103505",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://sourceforge.net/tracker/index.php?func=detail&aid=1204199&group_id=103505&atid=634992",
          "name" : "http://sourceforge.net/tracker/index.php?func=detail&aid=1204199&group_id=103505&atid=634992",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27268",
          "name" : "27268",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39639",
          "name" : "phprunningmanagement-index-xss(39639)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in PHP Running Management (phpRunMan) before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_running_management:phprunman:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0259",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "minimal_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "minimal_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28391",
          "name" : "28391",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27265",
          "name" : "27265",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39649",
          "name" : "minimalgallery-mgthumbs-file-include(39649)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4902",
          "name" : "4902",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) thumbcat and (2) thumb parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:minimal_design:minimal_gallery:0.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0260",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "minimal_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "minimal_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28391",
          "name" : "28391",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4902",
          "name" : "4902",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "minimal Gallery 0.8 allows remote attackers to obtain configuration information via a direct request to php_info.php, which calls the phpinfo function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:minimal_design:minimal_gallery:0.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0261",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "mambo_open_source",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forum.mambo-foundation.org/showthread.php?t=9651",
          "name" : "http://forum.mambo-foundation.org/showthread.php?t=9651",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28392",
          "name" : "28392",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27239",
          "name" : "27239",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39613",
          "name" : "mambo-search-dos(39613)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the search component and module in Mambo 4.5.x and 4.6.x allows remote attackers to cause a denial of service (query flood) via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo_open_source:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0262",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "agares_media",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpautovideo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.21",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27258",
          "name" : "27258",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39641",
          "name" : "agares-articleblock-sql-injection(39641)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4898",
          "name" : "4898",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4905",
          "name" : "4905",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute arbitrary SQL commands via the articlecat parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:agares_media:phpautovideo:2.21:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0263",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ingate",
            "product" : {
              "product_data" : [ {
                "product_name" : "firewall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.6",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "ingate_siparator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/40365",
          "name" : "40365",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28394",
          "name" : "28394",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.ingate.com/relnote-461.php",
          "name" : "http://www.ingate.com/relnote-461.php",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27222",
          "name" : "27222",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019176",
          "name" : "1019176",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019177",
          "name" : "1019177",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0108",
          "name" : "ADV-2008-0108",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The SIP module in Ingate Firewall before 4.6.1 and SIParator before 4.6.1 does not reuse SIP media ports in unspecified call hold and send-only stream scenarios, which allows remote attackers to cause a denial of service (port exhaustion) via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ingate:firewall:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.6"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ingate:ingate_siparator:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2011-03-08T03:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0264",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "meta_tags_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.x-1.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/209759",
          "name" : "http://drupal.org/node/209759",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28478",
          "name" : "28478",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0129",
          "name" : "ADV-2008-0129",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39638",
          "name" : "drupal-metatags-code-execution(39638)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Meta Tags (aka Nodewords) 5.x-1.6 module for Drupal, when images are permitted in node bodies, allows remote authenticated users to execute arbitrary code via unspecified vectors involving creation of a node."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:meta_tags_module:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.x-1.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0265",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "f5",
            "product" : {
              "product_data" : [ {
                "product_name" : "tmos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.4.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28505",
          "name" : "28505",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3545",
          "name" : "3545",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486217/100/0/threaded",
          "name" : "20080114 F5 BIG-IP Web Management List Search XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27272",
          "name" : "27272",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019190",
          "name" : "1019190",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0181",
          "name" : "ADV-2008-0181",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39632",
          "name" : "f5bigip-searchstring-xss(39632)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers to inject arbitrary web script or HTML via the SearchString parameter to (1) list_system.jsp, (2) list_pktfilter.jsp, (3) list_ltm.jsp, (4) resources_audit.jsp, and (5) list_asm.jsp in tmui/Control/jspmap/tmui/system/log/; and (6) list.jsp in certain directories."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:f5:tmos:9.4.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0266",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "eticket",
            "product" : {
              "product_data" : [ {
                "product_name" : "eticket",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28331",
          "name" : "28331",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3542",
          "name" : "3542",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485835/100/0/threaded",
          "name" : "20080106 eTicket 1.5.5.2 Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27173",
          "name" : "27173",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39490",
          "name" : "eticket-admin-csrf(39490)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the administrative password and possibly perform other administrative tasks.  NOTE: either the old password must be known, or the attacker must leverage a separate SQL injection vulnerability."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eticket:eticket:1.5.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0267",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "eticket",
            "product" : {
              "product_data" : [ {
                "product_name" : "eticket",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28331",
          "name" : "28331",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3542",
          "name" : "3542",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485835/100/0/threaded",
          "name" : "20080106 eTicket 1.5.5.2 Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27173",
          "name" : "27173",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39487",
          "name" : "eticket-admin-sql-injection(39487)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39489",
          "name" : "eticket-search-sql-injection(39489)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) status, (2) sort, and (3) way parameters to search.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (4) msg and (5) password parameters to admin.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eticket:eticket:1.5.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0268",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "eticket",
            "product" : {
              "product_data" : [ {
                "product_name" : "eticket",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28331",
          "name" : "28331",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3542",
          "name" : "3542",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485835/100/0/threaded",
          "name" : "20080106 eTicket 1.5.5.2 Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27173",
          "name" : "27173",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39488",
          "name" : "eticket-view-xss(39488)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eticket:eticket:1.5.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0269",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "sunos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28491",
          "name" : "28491",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-103188-1",
          "name" : "103188",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-66-201513-1",
          "name" : "201513",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27260",
          "name" : "27260",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019186",
          "name" : "1019186",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0130",
          "name" : "ADV-2008-0130",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39631",
          "name" : "solaris-dotoprocs-dos(39631)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5400",
          "name" : "oval:org.mitre.oval:def:5400",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the dotoprocs function in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0270",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "taskfreak",
            "product" : {
              "product_data" : [ {
                "product_name" : "taskfreak",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28448",
          "name" : "28448",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27257",
          "name" : "27257",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39645",
          "name" : "taskfreak-index-sql-injection(39645)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4899",
          "name" : "4899",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sContext parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:taskfreak:taskfreak:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.6.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0271",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "bueditor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7.x-1.0",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "5.x-1.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/208534",
          "name" : "http://drupal.org/node/208534",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28418",
          "name" : "28418",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0128",
          "name" : "ADV-2008-0128",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39614",
          "name" : "drupal-bueditor-csrf(39614)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The editor deletion form in BUEditor 4.7.x before 4.7.x-1.0 and 5.x before 5.x-1.1, a module for Drupal, does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete custom editor interfaces."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:bueditor:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.7.x-1.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:bueditor:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.x-1.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0272",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "drupal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0_rc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_rev_1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_rev_1.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1_rev1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/208562",
          "name" : "http://drupal.org/node/208562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28422",
          "name" : "28422",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28486",
          "name" : "28486",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27238",
          "name" : "27238",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vbdrupal.org/forum/showthread.php?p=6878",
          "name" : "http://www.vbdrupal.org/forum/showthread.php?p=6878",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vbdrupal.org/forum/showthread.php?t=1349",
          "name" : "http://www.vbdrupal.org/forum/showthread.php?t=1349",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0127",
          "name" : "ADV-2008-0127",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0134",
          "name" : "ADV-2008-0134",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39617",
          "name" : "drupal-aggregator-csrf(39617)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote attackers to delete items from a feed as privileged users."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.2.0_rc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7_rev_1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7_rev_1.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.1_rev1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.5.:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0273",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "drupal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0_rc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_rev_1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_rev_1.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1_rev1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/208564",
          "name" : "http://drupal.org/node/208564",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28422",
          "name" : "28422",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28486",
          "name" : "28486",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27238",
          "name" : "27238",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vbdrupal.org/forum/showthread.php?p=6878",
          "name" : "http://www.vbdrupal.org/forum/showthread.php?p=6878",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vbdrupal.org/forum/showthread.php?t=1349",
          "name" : "http://www.vbdrupal.org/forum/showthread.php?t=1349",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0127",
          "name" : "ADV-2008-0127",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0134",
          "name" : "ADV-2008-0134",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39619",
          "name" : "drupal-utf8-xss(39619)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML filtering, but are processed as UTF-8 by Internet Explorer, effectively removing characters from the document and defeating the HTML protection mechanism."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.2.0_rc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7_rev_1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7_rev_1.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.1_rev1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.5.:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0274",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "drupal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/208565",
          "name" : "http://drupal.org/node/208565",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28422",
          "name" : "28422",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28486",
          "name" : "28486",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27238",
          "name" : "27238",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vbdrupal.org/forum/showthread.php?p=6878",
          "name" : "http://www.vbdrupal.org/forum/showthread.php?p=6878",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vbdrupal.org/forum/showthread.php?t=1349",
          "name" : "http://www.vbdrupal.org/forum/showthread.php?t=1349",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0127",
          "name" : "ADV-2008-0127",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0134",
          "name" : "ADV-2008-0134",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39605",
          "name" : "drupal-theme-xss(39605)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0275",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "atom_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/208527",
          "name" : "http://drupal.org/node/208527",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39607",
          "name" : "drupal-atom-security-bypass(39607)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Atom 4.7 before 4.7.x-1.0 and 5.x before 5.x-1.0 module for Drupal does not properly manage permissions for node (1) titles, (2) teasers, and (3) bodies, which might allow remote attackers to gain access to syndicated content."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:atom_module:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.7"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:atom_module:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0276",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "drupal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0_rc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_rev_1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_rev_1.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1_rev1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/208524",
          "name" : "http://drupal.org/node/208524",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39606",
          "name" : "drupal-devel-variable-xss(39606)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.2.0_rc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7_rev_1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7_rev_1.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.1_rev1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.5.:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0277",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "fileshare_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7.x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.x",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/208537",
          "name" : "http://drupal.org/node/208537",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39609",
          "name" : "drupal-fileshare-code-execution(39609)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Fileshare module for Drupal allows remote authenticated users with node-creation privileges to execute arbitrary code via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:fileshare_module:4.7.x:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:fileshare_module:5.x:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 8.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 6.8,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0278",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "x7_group",
            "product" : {
              "product_data" : [ {
                "product_name" : "x7_chat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28503",
          "name" : "28503",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27277",
          "name" : "27277",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39656",
          "name" : "x7chatday-sql-injection(39656)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4907",
          "name" : "4907",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a sm_window action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:x7_group:x7_chat:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0279",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xforum",
            "product" : {
              "product_data" : [ {
                "product_name" : "xforum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27278",
          "name" : "27278",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39654",
          "name" : "xforum-liretopic-sql-injection(39654)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4908",
          "name" : "4908",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitrary SQL commands via the topic parameter.  NOTE: the categorie parameter might also be affected."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xforum:xforum:1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0280",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mtcms",
            "product" : {
              "product_data" : [ {
                "product_name" : "mtcms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28428",
          "name" : "28428",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3544",
          "name" : "3544",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486090/100/0/threaded",
          "name" : "20080110 MTCMS <=2.0 SQL Injection Vulnerbility",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27224",
          "name" : "27224",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39597",
          "name" : "mtcms-a-sql-injection(39597)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4882",
          "name" : "4882",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in MTCMS 2.0 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the (1) a or (2) cid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mtcms:mtcms:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T21:00Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0281",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "id-commerce",
            "product" : {
              "product_data" : [ {
                "product_name" : "id-commerce",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059533.html",
          "name" : "20080110 ID-Commerce Security Advisory - SLR-2007-001",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059537.html",
          "name" : "20080110 (( PoC)) ID-Commerce Security Advisory - SLR-2007-001 (( PoC))",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059538.html",
          "name" : "20080110 ID-Commerce Security Advisory - SLR-2007-001",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27220",
          "name" : "27220",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39594",
          "name" : "idcommerce-liste-sql-injection(39594)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in liste.php in ID-Commerce 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idFamille parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:id-commerce:id-commerce:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T21:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0282",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "domphp",
            "product" : {
              "product_data" : [ {
                "product_name" : "domphp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.81",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28393",
          "name" : "28393",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27212",
          "name" : "27212",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39593",
          "name" : "domphp-inscription-sql-injection(39593)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4880",
          "name" : "4880",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary SQL commands via the mail parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:domphp:domphp:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.81"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T21:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0283",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "domphp",
            "product" : {
              "product_data" : [ {
                "product_name" : "domphp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.81",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27226",
          "name" : "27226",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4883",
          "name" : "4883",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in /aides/index.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:domphp:domphp:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.81"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-15T21:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0284",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "simple_machines",
            "product" : {
              "product_data" : [ {
                "product_name" : "simple_machines_smf",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3540",
          "name" : "3540",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486074/100/0/threaded",
          "name" : "20080110 Simple Machines Forum Cross-Site Scripting Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27218",
          "name" : "27218",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39585",
          "name" : "simplemachinesforum-itemid-xss(39585)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) Itemid or (2) topic arguments."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:simple_machines:simple_machines_smf:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-15T21:00Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0285",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ngircd",
            "product" : {
              "product_data" : [ {
                "product_name" : "ngircd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.10.3",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.11.0-pre1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://arthur.barton.de/cgi-bin/viewcvs.cgi/ngircd/ngircd/src/ngircd/irc-channel.c?r1=1.40&r2=1.41&diff_format=h",
          "name" : "http://arthur.barton.de/cgi-bin/viewcvs.cgi/ngircd/ngircd/src/ngircd/irc-channel.c?r1=1.40&r2=1.41&diff_format=h",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=204834",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=204834",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://ngircd.barton.de/doc/ChangeLog",
          "name" : "http://ngircd.barton.de/doc/ChangeLog",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28425",
          "name" : "28425",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28673",
          "name" : "28673",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200801-13.xml",
          "name" : "GLSA-200801-13",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27318",
          "name" : "27318",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ngIRCd 0.10.x before 0.10.4 and 0.11.0 before 0.11.0-pre2 allows remote attackers to cause a denial of service (crash) via crafted IRC PART message, which triggers an invalid dereference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ngircd:ngircd:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.10.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ngircd:ngircd:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.11.0-pre1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T00:00Z",
    "lastModifiedDate" : "2008-09-05T21:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0286",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "article_dashboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "article_dashboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28495",
          "name" : "28495",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3546",
          "name" : "3546",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486323/100/0/threaded",
          "name" : "20080115 Article DashBoard all version SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486646/100/0/threaded",
          "name" : "20080116 Re: Article DashBoard all version SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27286",
          "name" : "27286",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39657",
          "name" : "articledashboard-login-sql-injection(39657)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in admin/login.php in Article Dashboard allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) password fields."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:article_dashboard:article_dashboard:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T01:00Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0287",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "visionburst",
            "product" : {
              "product_data" : [ {
                "product_name" : "vcart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28424",
          "name" : "28424",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27231",
          "name" : "27231",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39616",
          "name" : "vcart-checkout-index-file-include(39616)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4889",
          "name" : "4889",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in VisionBurst vcart 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php and (2) checkout.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:visionburst:vcart:3.3.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0288",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "imagealbum",
            "product" : {
              "product_data" : [ {
                "product_name" : "imagealbum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0b2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3548",
          "name" : "3548",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486162/100/0/threaded",
          "name" : "20080111 ImageAlbum Remote SQL Injection Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27240",
          "name" : "27240",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4895",
          "name" : "4895",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADomain.php, (2) classes/IACollection.php, and (3) classes/IAUser.php, as demonstrated via the id parameter in a collection.imageview action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:imagealbum:imagealbum:2.0.0b2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T02:00Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0289",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mansion_productions",
            "product" : {
              "product_data" : [ {
                "product_name" : "member_area_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3547",
          "name" : "3547",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486172/100/0/threaded",
          "name" : "20080111 Member Area System (MAS) Remote File Include Vulnerability (view_func.php)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486618/100/0/threaded",
          "name" : "20080118 Re: Member Area System (MAS) Remote File Include Vulnerability (view_func.php)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27244",
          "name" : "27244",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39611",
          "name" : "mas-viewfunc-file-include(39611)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remote attackers to execute arbitrary PHP code via a URL in the i parameter.  NOTE: a second vector might exist via the l parameter.  NOTE: as of 20080118, the vendor has disputed the set of affected versions, stating that the issue \"is already fixed, for almost a year.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mansion_productions:member_area_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T02:00Z",
    "lastModifiedDate" : "2018-10-15T21:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0290",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "digitalhive",
            "product" : {
              "product_data" : [ {
                "product_name" : "digitalhive",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0_rc2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27232",
          "name" : "27232",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39602",
          "name" : "digitalhive-base-sql-injection(39602)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4887",
          "name" : "4887",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the selectskin parameter to an unspecified program, or (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in the gestion_membre.php page to base.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:digitalhive:digitalhive:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0_rc2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0291",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hangzhou_rui-qiang",
            "product" : {
              "product_data" : [ {
                "product_name" : "richstrong_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28449",
          "name" : "28449",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486402/100/0/threaded",
          "name" : "20080116 RichStrong CMS (showproduct.asp?cat=) Remote SQL Injection Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27281",
          "name" : "27281",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27310",
          "name" : "27310",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39668",
          "name" : "richstrongcms-showproduct-sql-injection(39668)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4910",
          "name" : "4910",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL commands via the cat parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hangzhou_rui-qiang:richstrong_cms:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T22:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0292",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dansie",
            "product" : {
              "product_data" : [ {
                "product_name" : "photo_album",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28501",
          "name" : "28501",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39664",
          "name" : "dansiephotoalbum-photoalbum-xss(39664)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in photo_album.pl in Dansie Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dansie:photo_album:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-16T22:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0293",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freeseat",
            "product" : {
              "product_data" : [ {
                "product_name" : "freeseat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.5c",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28459",
          "name" : "28459",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=160239&release_id=568374",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=160239&release_id=568374",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39648",
          "name" : "freeseat-cron-security-bypass(39648)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in cron.php in FreeSeat before 1.1.5d, when format.php has certain modifications, allows remote attackers to bypass authentication and gain privileges via unspecified vectors related to the show_foot function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freeseat:freeseat:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.5c"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T22:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0294",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freeseat",
            "product" : {
              "product_data" : [ {
                "product_name" : "freeseat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.5c",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28459",
          "name" : "28459",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=568374&group_id=160239",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=568374&group_id=160239",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27270",
          "name" : "27270",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39647",
          "name" : "freeseat-seatlocking-security-bypass(39647)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the seat-locking implementation in FreeSeat before 1.1.5d allows attackers to book a seat more than once via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freeseat:freeseat:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.5c"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T22:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0295",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "videolan",
            "product" : {
              "product_data" : [ {
                "product_name" : "vlc_media_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.6d",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/vlcxhof-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/vlcxhof-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28383",
          "name" : "28383",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29284",
          "name" : "29284",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29766",
          "name" : "29766",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1543",
          "name" : "DSA-1543",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200803-13.xml",
          "name" : "GLSA-200803-13",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27221",
          "name" : "27221",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0105",
          "name" : "ADV-2008-0105",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14776",
          "name" : "oval:org.mitre.oval:def:14776",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in modules/access/rtsp/real_sdpplin.c in the Xine library, as used in VideoLAN VLC Media Player 0.8.6d and earlier, allows user-assisted remote attackers to cause a denial of service (crash) or execute arbitrary code via long Session Description Protocol (SDP) data."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.8.6d"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 8.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 6.8,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0296",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "videolan",
            "product" : {
              "product_data" : [ {
                "product_name" : "vlc_media_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.6d",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/vlcxhof-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/vlcxhof-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/29284",
          "name" : "29284",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29766",
          "name" : "29766",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1543",
          "name" : "DSA-1543",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200803-13.xml",
          "name" : "GLSA-200803-13",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0105",
          "name" : "ADV-2008-0105",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14597",
          "name" : "oval:org.mitre.oval:def:14597",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on Windows might allow remote RTSP servers to cause a denial of service (application crash) or execute arbitrary code via a long string."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "0.8.6d"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0297",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "keil_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "photokorn",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39652",
          "name" : "photokorn-update3-information-disclosure(39652)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4897",
          "name" : "4897",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its output."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:keil_software:photokorn:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T23:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0298",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3549",
          "name" : "3549",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.s21sec.com/avisos/s21sec-039-en.txt",
          "name" : "http://www.s21sec.com/avisos/s21sec-039-en.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486202/100/0/threaded",
          "name" : "20080112 Safari 2 Denial of Service",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27261",
          "name" : "27261",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39635",
          "name" : "safari-khtml-webkit-dos(39635)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a crafted web page, possibly involving a STYLE attribute of a DIV element."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.4:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-16T23:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0299",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "python_software_foundation",
            "product" : {
              "product_data" : [ {
                "product_name" : "paramiko",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=460706",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=460706",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://people.debian.org/~nion/nmu-diff/paramiko-1.6.4-1_1.6.4-1.1.patch",
          "name" : "http://people.debian.org/~nion/nmu-diff/paramiko-1.6.4-1_1.6.4-1.1.patch",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28488",
          "name" : "28488",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28510",
          "name" : "28510",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29168",
          "name" : "29168",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-07.xml",
          "name" : "GLSA-200803-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.lag.net/pipermail/paramiko/2008-January/000599.html",
          "name" : "http://www.lag.net/pipermail/paramiko/2008-January/000599.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27307",
          "name" : "27307",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=428727",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=428727",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39749",
          "name" : "paramiko-randompool-info-disclosure(39749)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00529.html",
          "name" : "FEDORA-2008-0644",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00594.html",
          "name" : "FEDORA-2008-0722",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python_software_foundation:paramiko:1.7.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-16T23:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0300",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mapbender",
            "product" : {
              "product_data" : [ {
                "product_name" : "mapbender",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29329",
          "name" : "29329",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redteam-pentesting.de/advisories/rt-sa-2008-001.php",
          "name" : "http://www.redteam-pentesting.de/advisories/rt-sa-2008-001.php",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28195",
          "name" : "28195",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41131",
          "name" : "mapbender-mapfiler-code-execution(41131)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5232",
          "name" : "5232",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "mapFiler.php in Mapbender 2.4 to 2.4.4 allows remote attackers to execute arbitrary PHP code via PHP code sequences in the factor parameter, which are not properly handled when accessing a filename that contains those sequences."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mapbender:mapbender:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mapbender:mapbender:2.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mapbender:mapbender:2.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mapbender:mapbender:2.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mapbender:mapbender:2.4.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-11T23:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0301",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mapbender",
            "product" : {
              "product_data" : [ {
                "product_name" : "mapbender",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=120523564611595&w=2",
          "name" : "20080311 Advisory: SQL-Injections in Mapbender",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29329",
          "name" : "29329",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3728",
          "name" : "3728",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.redteam-pentesting.de/advisories/rt-sa-2008-002.php",
          "name" : "http://www.redteam-pentesting.de/advisories/rt-sa-2008-002.php",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489383/100/0/threaded",
          "name" : "20080311 Advisory: SQL-Injections in Mapbender",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28193",
          "name" : "28193",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41139",
          "name" : "mapbender-gaz-sql-injection(41139)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5233",
          "name" : "5233",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Mapbender 2.4.4 allow remote attackers to execute arbitrary SQL commands via the gaz parameter to mod_gazetteer_edit.php and other unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mapbender:mapbender:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mapbender:mapbender:2.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mapbender:mapbender:2.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mapbender:mapbender:2.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mapbender:mapbender:2.4.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-11T23:44Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0302",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "apt-listchanges",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.81",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://git.madism.org/?p=apt-listchanges.git;a=commitdiff;h=1bcfbf3dc55413bb83a1782dc9a54515a963fb32",
          "name" : "http://git.madism.org/?p=apt-listchanges.git;a=commitdiff;h=1bcfbf3dc55413bb83a1782dc9a54515a963fb32",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://packages.debian.org/changelogs/pool/main/a/apt-listchanges/apt-listchanges_2.82/changelog",
          "name" : "http://packages.debian.org/changelogs/pool/main/a/apt-listchanges/apt-listchanges_2.82/changelog",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28513",
          "name" : "28513",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28574",
          "name" : "28574",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1465",
          "name" : "DSA-1465",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27331",
          "name" : "27331",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-572-1",
          "name" : "USN-572-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Untrusted search path vulnerability in apt-listchanges.py in apt-listchanges before 2.82 allows local users to execute arbitrary code via a malicious apt-listchanges program in the current working directory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:debian:apt-listchanges:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.81"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T02:00Z",
    "lastModifiedDate" : "2008-09-05T21:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0303",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "canon",
            "product" : {
              "product_data" : [ {
                "product_name" : "i-sensys",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "lbp3360",
                    "version_affected" : "="
                  }, {
                    "version_value" : "lbp3460",
                    "version_affected" : "="
                  }, {
                    "version_value" : "lbp5360",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "imagepress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "c1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "imagerunner",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "85plus",
                    "version_affected" : "="
                  }, {
                    "version_value" : "105plus",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2230",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2270",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2570c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2570ci",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2870",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3025",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3025n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3035",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3035n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3045",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3045n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3170c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3170ci",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3180c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3180ci",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3530",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3570",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4570",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5055",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5055n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5065",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5065n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5075",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5075n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5570",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5800c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5800cn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6570",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6800c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6800cn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7086",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7095",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7095p",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7105",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8070",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c2380i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c2620",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c2620n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c2880",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c2880i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c3220n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c3380",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c3380i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c4080i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c4580i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c5185i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c5870",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c5870i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c5880",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c5880i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c6870i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c6880",
                    "version_affected" : "="
                  }, {
                    "version_value" : "c6880i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "clc4040",
                    "version_affected" : "="
                  }, {
                    "version_value" : "clc5151",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "imagerunner_2620",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "imagerunner_5000i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "imagerunner_5020",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "imagerunner_6870",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "imagerunner_8500",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "imagerunner_9070",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "imagerunner_c3200",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "imagerunner_c3220",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "imagerunner_c6800",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://itso.iu.edu/20080229_Canon_MFD_FTP_bounce_attack",
          "name" : "http://itso.iu.edu/20080229_Canon_MFD_FTP_bounce_attack",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://jvn.jp/en/jp/JVN10056705/index.html",
          "name" : "JVN#10056705",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000013.html",
          "name" : "JVNDB-2008-000013",
          "refsource" : "JVNDB",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019528",
          "name" : "1019528",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/568073",
          "name" : "VU#568073",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28042",
          "name" : "28042",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.usa.canon.com/html/security/pdf/CVA-001.pdf",
          "name" : "http://www.usa.canon.com/html/security/pdf/CVA-001.pdf",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The FTP print feature in multiple Canon printers, including imageRUNNER and imagePRESS, allow remote attackers to use the server as an inadvertent proxy via a modified PORT command, aka FTP bounce."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:i-sensys:lbp3360:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:i-sensys:lbp3460:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:i-sensys:lbp5360:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagepress:c1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:85plus:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:105plus:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:2230:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:2270:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:2570c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:2570ci:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:2870:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:3025:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:3025n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:3035:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:3035n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:3045:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:3045n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:3170c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:3170ci:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:3180c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:3180ci:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:3530:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:3570:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:4570:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:5055:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:5055n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:5065:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:5065n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:5075:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:5075n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:5570:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:5800c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:5800cn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:6570:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:6800c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:6800cn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:7086:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:7095:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:7095p:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:7105:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:8070:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c2380i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c2620:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c2620n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c2880:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c2880i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c3220n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c3380:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c3380i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c4080i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c4580i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c5185i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c5870:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c5870i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c5880:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c5880i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c6870i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c6880:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:c6880i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:clc4040:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner:clc5151:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner_2620:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner_5000i:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner_5020:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner_6870:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner_8500:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner_9070:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner_c3200:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner_c3220:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:canon:imagerunner_c6800:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-29T02:44Z",
    "lastModifiedDate" : "2009-03-13T05:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0304",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.7",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=668",
          "name" : "20080226 Mozilla Thunderbird MIME External-Body Heap Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29098",
          "name" : "29098",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29133",
          "name" : "29133",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29167",
          "name" : "29167",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29211",
          "name" : "29211",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30327",
          "name" : "30327",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31043",
          "name" : "31043",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31253",
          "name" : "31253",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/33433",
          "name" : "33433",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019504",
          "name" : "1019504",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.445399",
          "name" : "SSA:2008-061-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1",
          "name" : "239546",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1621",
          "name" : "DSA-1621",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2009/dsa-1697",
          "name" : "DSA-1697",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml",
          "name" : "GLSA-200805-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/661651",
          "name" : "VU#661651",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:062",
          "name" : "MDVSA-2008:062",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-12.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-12.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28012",
          "name" : "28012",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-582-1",
          "name" : "USN-582-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-582-2",
          "name" : "USN-582-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2091/references",
          "name" : "ADV-2008-2091",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11075",
          "name" : "oval:org.mitre.oval:def:11075",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html",
          "name" : "FEDORA-2008-2060",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html",
          "name" : "FEDORA-2008-2118",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "1.1.7"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "2.0.0.9"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-29T19:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0306",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sap",
            "product" : {
              "product_data" : [ {
                "product_name" : "maxdb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.6.0.37",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=670",
          "name" : "20080310 SAP MaxDB sdbstarter Privilege Escalation Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29312",
          "name" : "29312",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28185",
          "name" : "28185",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019570",
          "name" : "1019570",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0844/references",
          "name" : "ADV-2008-0844",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41104",
          "name" : "maxdb-sdbstarter-privilege-escalation(41104)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "sdbstarter in SAP MaxDB 7.6.0.37, and possibly other versions, allows local users to execute arbitrary commands by using unspecified environment variables to modify configuration settings."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sap:maxdb:7.6.0.37:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-11T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0307",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sap",
            "product" : {
              "product_data" : [ {
                "product_name" : "maxdb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.6.0.37",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=669",
          "name" : "20080310 SAP MaxDB Signedness Error Heap Corruption Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29312",
          "name" : "29312",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28183",
          "name" : "28183",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019571",
          "name" : "1019571",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0844/references",
          "name" : "ADV-2008-0844",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41107",
          "name" : "maxdb-vserver-code-execution(41107)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown vectors that trigger heap corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sap:maxdb:7.6.0.37:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-11T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0308",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "scan_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.4.24",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_clearswift",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.16.39",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_filtering_domino_mpe",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.12",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_messaging",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.16.39",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_microsoft_sharepoint",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.16.39",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_ms_isa",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.16.39",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_network_attached_storage",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.16.39",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_scan_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.16.39",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_scan_engine_caching",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.16.39",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_mail_security_exchange",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.6.5.12",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "5.0.4.363",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=666",
          "name" : "20080226 Symantec Scan Engine 5.1.2 RAR File Denial of Service Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29140",
          "name" : "29140",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27911",
          "name" : "27911",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019503",
          "name" : "1019503",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.symantec.com/avcenter/security/Content/2008.02.27.html",
          "name" : "http://www.symantec.com/avcenter/security/Content/2008.02.27.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0680",
          "name" : "ADV-2008-0680",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to cause a denial of service (memory consumption) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:scan_engine:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1.4.24"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_clearswift:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3.16.39"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_filtering_domino_mpe:*:*:aix:*:*:*:*:*",
          "versionEndIncluding" : "3.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_filtering_domino_mpe:*:*:linux:*:*:*:*:*",
          "versionEndIncluding" : "3.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_filtering_domino_mpe:*:*:solaris:*:*:*:*:*",
          "versionEndIncluding" : "3.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_messaging:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3.16.39"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_microsoft_sharepoint:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3.16.39"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_ms_isa:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3.16.39"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_network_attached_storage:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3.16.39"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_scan_engine:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3.16.39"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_scan_engine_caching:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3.16.39"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_mail_security_exchange:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.6.5.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_mail_security_exchange:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0.4.363"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-28T20:44Z",
    "lastModifiedDate" : "2011-03-08T03:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0309",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "scan_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.4.24",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_filtering_domino_mpe",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.12",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_network_attached_storage",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.16.39",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_scan_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.16.39",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_scan_engine_caching",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.16.39",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_scan_engine_clearswift",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.16.39",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_scan_engine_for_microsoft_sharepoint",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.16.39",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_scan_engine_for_ms_isa",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.16.39",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_scan_engine_messaging",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.16.39",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "symantec_mail_security_for_microsoft_exchange",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.6.5.12",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "5.0.4.363",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=667",
          "name" : "20080226 Symantec Scan Engine 5.1.2 RAR File Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29140",
          "name" : "29140",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27913",
          "name" : "27913",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019503",
          "name" : "1019503",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.symantec.com/avcenter/security/Content/2008.02.27.html",
          "name" : "http://www.symantec.com/avcenter/security/Content/2008.02.27.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0680",
          "name" : "ADV-2008-0680",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:scan_engine:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1.4.24"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_filtering_domino_mpe:*:*:aix:*:*:*:*:*",
          "versionEndIncluding" : "3.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_filtering_domino_mpe:*:*:linux:*:*:*:*:*",
          "versionEndIncluding" : "3.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_filtering_domino_mpe:*:*:solaris:*:*:*:*:*",
          "versionEndIncluding" : "3.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_network_attached_storage:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3.16.39"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_scan_engine:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3.16.39"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_scan_engine_caching:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3.16.39"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_scan_engine_clearswift:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3.16.39"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_scan_engine_for_microsoft_sharepoint:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3.16.39"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_scan_engine_for_ms_isa:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3.16.39"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_scan_engine_messaging:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3.16.39"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_mail_security_for_microsoft_exchange:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.6.5.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_mail_security_for_microsoft_exchange:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0.4.363"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-28T20:44Z",
    "lastModifiedDate" : "2011-03-08T03:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0310",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sco",
            "product" : {
              "product_data" : [ {
                "product_name" : "unixware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://ftp.sco.com/pub/unixware7/714/security/p534589/p534589.txt",
          "name" : "SCOSA-2008.1",
          "refsource" : "SCO",
          "tags" : [ ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=676",
          "name" : "20080403 SCO UnixWare pkgadd Directory Traversal Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29657",
          "name" : "29657",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.sco.com/support/update/download/release.php?rid=324",
          "name" : "http://www.sco.com/support/update/download/release.php?rid=324",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019787",
          "name" : "1019787",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41759",
          "name" : "sco-unixware-pkgadd-directory-traversal(41759)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5355",
          "name" : "5355",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append to arbitrary files via \"..\" sequences in an unspecified environment variable, probably PKGINST."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sco:unixware:7.1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-07T17:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0311",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "borland",
            "product" : {
              "product_data" : [ {
                "product_name" : "caliberrm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2006",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=675",
          "name" : "20080402 Borland CaliberRM StarTeam Multicast Service Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29631",
          "name" : "29631",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019786",
          "name" : "1019786",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28602",
          "name" : "28602",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1100",
          "name" : "ADV-2008-1100",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41647",
          "name" : "starteam-pgmwebhandlerparserequest-bo(41647)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the PGMWebHandler::parse_request function in the StarTeam Multicast Service component (STMulticastService) 6.4 in Borland CaliberRM 2006 allows remote attackers to execute arbitrary code via a large HTTP request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:borland:caliberrm:2006:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-06T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0312",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "norton_360",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "norton_antivirus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2008",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "norton_internet_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2008",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "norton_system_works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2008",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=677",
          "name" : "20080402 Symantec Norton Internet Security 2008 ActiveX Control Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29660",
          "name" : "29660",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityresponse.symantec.com/avcenter/security/Content/2008.04.02a.html",
          "name" : "http://securityresponse.symantec.com/avcenter/security/Content/2008.04.02a.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28507",
          "name" : "28507",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019751",
          "name" : "1019751",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019752",
          "name" : "1019752",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019753",
          "name" : "1019753",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1077/references",
          "name" : "ADV-2008-1077",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41629",
          "name" : "symantec-autofixtool-bo(41629)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the AutoFix Support Tool ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products, including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, allows remote attackers to execute arbitrary code via a long argument to the GetEventLogInfo method.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:symantec:norton_360:1.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:2006:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:2007:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:2008:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:2006:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:2007:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:2008:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:symantec:norton_system_works:2006:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:symantec:norton_system_works:2007:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:symantec:norton_system_works:2008:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-08T17:05Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0313",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "norton_360",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "norton_antivirus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2008",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "norton_internet_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2008",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "system_works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2008",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=678",
          "name" : "20080402 Symantec Internet Security 2008 ActiveDataInfo.LaunchProcess Design Error Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29660",
          "name" : "29660",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityresponse.symantec.com/avcenter/security/Content/2008.04.02a.html",
          "name" : "http://securityresponse.symantec.com/avcenter/security/Content/2008.04.02a.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28509",
          "name" : "28509",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019751",
          "name" : "1019751",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019752",
          "name" : "1019752",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019753",
          "name" : "1019753",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1077/references",
          "name" : "ADV-2008-1077",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41631",
          "name" : "symantec-autofixtool-code-execution(41631)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ActiveDataInfo.LaunchProcess method in the SymAData.ActiveDataInfo.1 ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, does not properly determine the location of the AutoFix Tool, which allows remote attackers to execute arbitrary code via a remote (1) WebDAV or (2) SMB share."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_360:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:2008:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:2008:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:system_works:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:system_works:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:system_works:2008:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-08T17:05Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0314",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clam_anti-virus",
            "product" : {
              "product_data" : [ {
                "product_name" : "clamav",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.92.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kolab.org/security/kolab-vendor-notice-20.txt",
          "name" : "http://kolab.org/security/kolab-vendor-notice-20.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=686",
          "name" : "20080414 ClamAV libclamav PeSpin Heap Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html",
          "name" : "APPLE-SA-2008-09-15",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00009.html",
          "name" : "SUSE-SA:2008:024",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29863",
          "name" : "29863",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29886",
          "name" : "29886",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29891",
          "name" : "29891",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29975",
          "name" : "29975",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30253",
          "name" : "30253",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30328",
          "name" : "30328",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31576",
          "name" : "31576",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31882",
          "name" : "31882",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200805-19.xml",
          "name" : "GLSA-200805-19",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog",
          "name" : "http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://up2date.astaro.com/2008/08/up2date_asg_v7300_ga_released.html",
          "name" : "http://up2date.astaro.com/2008/08/up2date_asg_v7300_ga_released.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1549",
          "name" : "DSA-1549",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/858595",
          "name" : "VU#858595",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:088",
          "name" : "MDVSA-2008:088",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28784",
          "name" : "28784",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019851",
          "name" : "1019851",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-260A.html",
          "name" : "TA08-260A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1227/references",
          "name" : "ADV-2008-1227",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2584",
          "name" : "ADV-2008-2584",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41823",
          "name" : "clamav-spin-bo(41823)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00576.html",
          "name" : "FEDORA-2008-3358",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00625.html",
          "name" : "FEDORA-2008-3420",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00249.html",
          "name" : "FEDORA-2008-3900",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://wwws.clamav.net/bugzilla/show_bug.cgi?id=876",
          "name" : "https://wwws.clamav.net/bugzilla/show_bug.cgi?id=876",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in spin.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted PeSpin packed PE binary with a modified length value."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.92.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-16T15:05Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0318",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clam_anti-virus",
            "product" : {
              "product_data" : [ {
                "product_name" : "clamav",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.92",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=209915",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=209915",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://kolab.org/security/kolab-vendor-notice-19.txt",
          "name" : "http://kolab.org/security/kolab-vendor-notice-19.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=658",
          "name" : "20080212 ClamAV libclamav PE File Integer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00008.html",
          "name" : "SUSE-SR:2008:004",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28907",
          "name" : "28907",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28913",
          "name" : "28913",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28949",
          "name" : "28949",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29001",
          "name" : "29001",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29026",
          "name" : "29026",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29048",
          "name" : "29048",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29060",
          "name" : "29060",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200802-09.xml",
          "name" : "GLSA-200802-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019394",
          "name" : "1019394",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=575703",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=575703",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/512985d2cd3090bfb93dcb7b551179cf.html",
          "name" : "http://support.novell.com/techcenter/psdb/512985d2cd3090bfb93dcb7b551179cf.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1497",
          "name" : "DSA-1497",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:088",
          "name" : "MDVSA-2008:088",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27751",
          "name" : "27751",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0503",
          "name" : "ADV-2008-0503",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0606",
          "name" : "ADV-2008-0606",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00462.html",
          "name" : "FEDORA-2008-1608",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00481.html",
          "name" : "FEDORA-2008-1625",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in the cli_scanpe function in libclamav in ClamAV before 0.92.1, as used in clamd, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Petite packed PE file, which triggers a heap-based buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.92"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T20:00Z",
    "lastModifiedDate" : "2011-03-07T05:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0320",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openoffice",
            "product" : {
              "product_data" : [ {
                "product_name" : "openoffice.org",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=694",
          "name" : "20080417 Multiple Vendor OpenOffice OLE DocumentSummaryInformation Heap Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29844",
          "name" : "29844",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29852",
          "name" : "29852",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29864",
          "name" : "29864",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29871",
          "name" : "29871",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29910",
          "name" : "29910",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29913",
          "name" : "29913",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29987",
          "name" : "29987",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30100",
          "name" : "30100",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30179",
          "name" : "30179",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200805-16.xml",
          "name" : "GLSA-200805-16",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-231642-1",
          "name" : "231642",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1547",
          "name" : "DSA-1547",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:090",
          "name" : "MDVSA-2008:090",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:095",
          "name" : "MDVSA-2008:095",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2008_23_openoffice.html",
          "name" : "SUSE-SA:2008:023",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.openoffice.org/security/bulletin.html",
          "name" : "http://www.openoffice.org/security/bulletin.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.openoffice.org/security/cves/CVE-2007-4770.html",
          "name" : "http://www.openoffice.org/security/cves/CVE-2007-4770.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.openoffice.org/security/cves/CVE-2007-5745.html",
          "name" : "http://www.openoffice.org/security/cves/CVE-2007-5745.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.openoffice.org/security/cves/CVE-2008-0320.html",
          "name" : "http://www.openoffice.org/security/cves/CVE-2008-0320.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0175.html",
          "name" : "RHSA-2008:0175",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0176.html",
          "name" : "RHSA-2008:0176",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28819",
          "name" : "28819",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019890",
          "name" : "1019890",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-609-1",
          "name" : "USN-609-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1253/references",
          "name" : "ADV-2008-1253",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1375/references",
          "name" : "ADV-2008-1375",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41860",
          "name" : "openoffice-ole-bo(41860)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10318",
          "name" : "oval:org.mitre.oval:def:10318",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00448.html",
          "name" : "FEDORA-2008-3251",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openoffice:openoffice.org:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openoffice:openoffice.org:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openoffice:openoffice.org:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openoffice:openoffice.org:2.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openoffice:openoffice.org:2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openoffice:openoffice.org:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.3.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-17T19:05Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0322",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=699",
          "name" : "20080512 Microsoft Windows I2O Filter Utility Driver (i2omgmt.sys) Local Privilege Escalation Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/30203",
          "name" : "30203",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29171",
          "name" : "29171",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020006",
          "name" : "1020006",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1476/references",
          "name" : "ADV-2008-1476",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42358",
          "name" : "win-i2omgmt-code-execution(42358)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The I2O Utility Filter driver (i2omgmt.sys) 5.1.2600.2180 for Microsoft Windows XP sets Everyone/Write permissions for the \"\\\\.\\I2OExc\" device interface, which allows local users to gain privileges.  NOTE: this issue can be leveraged to overwrite arbitrary memory and execute code via an IOCTL call with a crafted DeviceObject pointer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-05-13T20:20Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0324",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "vpn_client",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.2.0090",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28472",
          "name" : "28472",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27289",
          "name" : "27289",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019240",
          "name" : "1019240",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0170",
          "name" : "ADV-2008-0170",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39694",
          "name" : "cisco-vpnclient-cvpndrva-dos(39694)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4911",
          "name" : "4911",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco Systems VPN Client IPSec Driver (CVPNDRVA.sys) 5.0.02.0090 allows local users to cause a denial of service (crash) by calling the 0x80002038 IOCTL with a small size value, which triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:vpn_client:5.0.2.0090:*:windows:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T03:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0325",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fascript",
            "product" : {
              "product_data" : [ {
                "product_name" : "fapersian_petition",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28522",
          "name" : "28522",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27302",
          "name" : "27302",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39716",
          "name" : "fascriptfapersian-show-sql-injection(39716)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4916",
          "name" : "4916",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in show.php in FaScript FaPersian Petition allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fascript:fapersian_petition:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0326",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fascript",
            "product" : {
              "product_data" : [ {
                "product_name" : "fapersianhack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28565",
          "name" : "28565",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27302",
          "name" : "27302",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39717",
          "name" : "fascriptfapersianhack-show-sql-injection(39717)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4917",
          "name" : "4917",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to show.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fascript:fapersianhack:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0327",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fascript",
            "product" : {
              "product_data" : [ {
                "product_name" : "famp3",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/40330",
          "name" : "40330",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28566",
          "name" : "28566",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27302",
          "name" : "27302",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39714",
          "name" : "fascriptfamp3-show-sql-injection(39714)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4914",
          "name" : "4914",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in show.php in FaScript FaMp3 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fascript:famp3:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0328",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fascript",
            "product" : {
              "product_data" : [ {
                "product_name" : "faname",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28528",
          "name" : "28528",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27303",
          "name" : "27303",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39715",
          "name" : "fascriptfaname-page-sql-injection(39715)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4915",
          "name" : "4915",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in page.php in FaScript FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fascript:faname:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0329",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "julien_plesniak",
            "product" : {
              "product_data" : [ {
                "product_name" : "lulieblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28432",
          "name" : "28432",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27290",
          "name" : "27290",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39669",
          "name" : "lulieblog-admin-security-bypass(39669)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4912",
          "name" : "4912",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which allows remote attackers to accept comments, delete comments, and delete articles via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:julien_plesniak:lulieblog:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:julien_plesniak:lulieblog:1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0330",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "radiator",
            "product" : {
              "product_data" : [ {
                "product_name" : "radius_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.17.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28463",
          "name" : "28463",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.open.com.au/radiator/history.html",
          "name" : "http://www.open.com.au/radiator/history.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27306",
          "name" : "27306",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0598",
          "name" : "ADV-2008-0598",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39730",
          "name" : "radiator-radius-dos(39730)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40664",
          "name" : "osc-radiator-unspecified-dos(40664)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Open System Consultants (OSC) Radiator before 4.0 allows remote attackers to cause a denial of service (daemon crash) via malformed RADIUS requests, as demonstrated by packets sent by nmap."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:radiator:radius_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.17.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T22:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0331",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "funkwerk",
            "product" : {
              "product_data" : [ {
                "product_name" : "system_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4.1_patch_8",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          }, {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/42782",
          "name" : "42782",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28085",
          "name" : "28085",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.funkwerk-ec.com/portal/downloadcenter/dateien/x2300/r7401p09/readme_741p9_en.pdf",
          "name" : "http://www.funkwerk-ec.com/portal/downloadcenter/dateien/x2300/r7401p09/readme_741p9_en.pdf",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27314",
          "name" : "27314",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39731",
          "name" : "x2300-dns-dos(39731)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Funkwerk System Software before 7.4.1 PATCH 9 for certain Funkwerk Router / VPN devices allows remote attackers to cause a denial of service (panic and reboot) via unspecified DNS requests."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:funkwerk:x2300:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:funkwerk:system_software:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "7.4.1_patch_8"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T22:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0332",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aria",
            "product" : {
              "product_data" : [ {
                "product_name" : "aria",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.99-6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/486406/100/0/threaded",
          "name" : "20080116 [DSECRG-08-002] Local File Include in arias 0.99-6",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27311",
          "name" : "27311",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39712",
          "name" : "aria-effect-file-include(39712)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4920",
          "name" : "4920",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aria:aria:0.99-6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T22:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0333",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "afterlogic",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailbee_webmail_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "asp.net",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28521",
          "name" : "28521",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27312",
          "name" : "27312",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39724",
          "name" : "mailbeewebmail-download-directory-traversal(39724)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4921",
          "name" : "4921",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read arbitrary files via a .. (dot dot) in the temp_filename parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:afterlogic:mailbee_webmail_pro:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:asp.net:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0334",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pmachine",
            "product" : {
              "product_data" : [ {
                "product_name" : "pmachine_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.org/0801-exploits/pMachinePro-241-xss.txt",
          "name" : "http://packetstormsecurity.org/0801-exploits/pMachinePro-241-xss.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27282",
          "name" : "27282",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the L_PREF_NAME[855] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pmachine:pmachine_pro:2.4.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-17T22:00Z",
    "lastModifiedDate" : "2008-09-05T21:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0335",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bugtracker.net",
            "product" : {
              "product_data" : [ {
                "product_name" : "bugtracker.net",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28481",
          "name" : "28481",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=568160",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=568160",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://sourceforge.net/tracker/index.php?func=detail&aid=1867089&group_id=66812&atid=515837",
          "name" : "http://sourceforge.net/tracker/index.php?func=detail&aid=1867089&group_id=66812&atid=515837",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27275",
          "name" : "27275",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39650",
          "name" : "bugtrackernet-bug-xss(39650)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in BugTracker.NET before 2.7.2 allows remote attackers to inject arbitrary web script or HTML via an arbitrary custom text field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bugtracker.net:bugtracker.net:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.7.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-17T22:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0336",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bugtracker.net",
            "product" : {
              "product_data" : [ {
                "product_name" : "bugtracker.net",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28481",
          "name" : "28481",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=66812&release_id=568160",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=66812&release_id=568160",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://sourceforge.net/tracker/index.php?func=detail&aid=1867089&group_id=66812&atid=515837",
          "name" : "http://sourceforge.net/tracker/index.php?func=detail&aid=1867089&group_id=66812&atid=515837",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39651",
          "name" : "bugtrackernet-http-csrf(39651)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site request forgery (CSRF) vulnerabilities in BugTracker.NET before 2.7.2 allow remote attackers to delete arbitrary bugs and perform other administrative tasks via unspecified vectors, possibly related to delete_*.aspx pages, and massedit.aspx, subscribe.aspx, flag.aspx, and relationships.aspx."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bugtracker.net:bugtracker.net:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.7.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-17T22:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0337",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "miniweb_http_server",
            "product" : {
              "product_data" : [ {
                "product_name" : "miniweb_http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.19",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28512",
          "name" : "28512",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.bugtraq.ir/adv/miniweb_english.pdf",
          "name" : "http://www.bugtraq.ir/adv/miniweb_english.pdf",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27319",
          "name" : "27319",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0176",
          "name" : "ADV-2008-0176",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39718",
          "name" : "miniweb-mwprocessreadsocket-bo(39718)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4923",
          "name" : "4923",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary code via a long URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:miniweb_http_server:miniweb_http_server:0.8.19:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0338",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "miniweb_http_server",
            "product" : {
              "product_data" : [ {
                "product_name" : "miniweb_http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.19",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28512",
          "name" : "28512",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.bugtraq.ir/adv/miniweb_english.pdf",
          "name" : "http://www.bugtraq.ir/adv/miniweb_english.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27319",
          "name" : "27319",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0176",
          "name" : "ADV-2008-0176",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39713",
          "name" : "miniweb-mwgetlocal-directory-traversal(39713)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4923",
          "name" : "4923",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .%2e (partially encoded dot dot) or (2) %2e%2e (encoded dot dot) in the URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:miniweb_http_server:miniweb_http_server:0.8.19:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0339",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2.0.8dv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120058413923005&w=2",
          "name" : "SSRT061201",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28518",
          "name" : "28518",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28556",
          "name" : "28556",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019218",
          "name" : "1019218",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27229",
          "name" : "27229",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-017A.html",
          "name" : "TA08-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0150",
          "name" : "ADV-2008-0150",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0180",
          "name" : "ADV-2008-0180",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB01."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8dv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T23:00Z",
    "lastModifiedDate" : "2012-10-23T02:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0340",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8dv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.0.6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.49",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120058413923005&w=2",
          "name" : "SSRT061201",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28518",
          "name" : "28518",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28556",
          "name" : "28556",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019218",
          "name" : "1019218",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27229",
          "name" : "27229",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-017A.html",
          "name" : "TA08-017A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0150",
          "name" : "ADV-2008-0150",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0180",
          "name" : "ADV-2008-0180",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote attack vectors, related to the (1) Advanced Queuing component (DB02) and (2) Oracle Spatial component (DB04)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8dv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:11.1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.49:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T23:00Z",
    "lastModifiedDate" : "2012-10-23T02:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0341",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120058413923005&w=2",
          "name" : "SSRT061201",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28518",
          "name" : "28518",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28556",
          "name" : "28556",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019218",
          "name" : "1019218",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27229",
          "name" : "27229",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-017A.html",
          "name" : "TA08-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0150",
          "name" : "ADV-2008-0150",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0180",
          "name" : "ADV-2008-0180",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.0.1.5 FIPS+ and 10.1.0.5 has unknown impact and remote attack vectors, aka DB03."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T23:00Z",
    "lastModifiedDate" : "2012-10-23T02:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0342",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120058413923005&w=2",
          "name" : "SSRT061201",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28518",
          "name" : "28518",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28556",
          "name" : "28556",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019218",
          "name" : "1019218",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27229",
          "name" : "27229",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-017A.html",
          "name" : "TA08-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0150",
          "name" : "ADV-2008-0150",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0180",
          "name" : "ADV-2008-0180",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Upgrade/Downgrade component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB05."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T23:00Z",
    "lastModifiedDate" : "2012-10-23T02:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0343",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8dv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.0.6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.49",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120058413923005&w=2",
          "name" : "SSRT061201",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28518",
          "name" : "28518",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28556",
          "name" : "28556",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019218",
          "name" : "1019218",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27229",
          "name" : "27229",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-017A.html",
          "name" : "TA08-017A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0150",
          "name" : "ADV-2008-0150",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0180",
          "name" : "ADV-2008-0180",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and remote attack vectors, aka DB06."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8dv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:11.1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.49:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T23:00Z",
    "lastModifiedDate" : "2012-10-23T02:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0344",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8dv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.0.6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.49",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120058413923005&w=2",
          "name" : "SSRT061201",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28518",
          "name" : "28518",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28556",
          "name" : "28556",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019218",
          "name" : "1019218",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27229",
          "name" : "27229",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-017A.html",
          "name" : "TA08-017A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0150",
          "name" : "ADV-2008-0150",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0180",
          "name" : "ADV-2008-0180",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka DB07."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8dv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:11.1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.49:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T23:00Z",
    "lastModifiedDate" : "2012-10-23T02:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0345",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8dv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.0.6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.49",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120058413923005&w=2",
          "name" : "SSRT061201",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28518",
          "name" : "28518",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28556",
          "name" : "28556",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019218",
          "name" : "1019218",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27229",
          "name" : "27229",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-017A.html",
          "name" : "TA08-017A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0150",
          "name" : "ADV-2008-0150",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0180",
          "name" : "ADV-2008-0180",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8dv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:11.1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.49:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T23:00Z",
    "lastModifiedDate" : "2012-10-23T02:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0346",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8dv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.0.6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.49",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120058413923005&w=2",
          "name" : "SSRT061201",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/40294",
          "name" : "40294",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28518",
          "name" : "28518",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28556",
          "name" : "28556",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019218",
          "name" : "1019218",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27229",
          "name" : "27229",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-017A.html",
          "name" : "TA08-017A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0150",
          "name" : "ADV-2008-0150",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0180",
          "name" : "ADV-2008-0180",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 and E-Business Suite 11.5.10.2 has unknown impact and remote attack vectors, aka AS01."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8dv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:11.1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.49:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T23:00Z",
    "lastModifiedDate" : "2012-10-23T02:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0347",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "application_server_9i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8dv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.0.6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.49",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120058413923005&w=2",
          "name" : "SSRT061201",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28518",
          "name" : "28518",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28556",
          "name" : "28556",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019218",
          "name" : "1019218",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.petefinnigan.com/Advisory_CPU_Jan_2008.htm",
          "name" : "http://www.petefinnigan.com/Advisory_CPU_Jan_2008.htm",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487322/100/100/threaded",
          "name" : "20080130 PeteFinnigan.com Limited advisory for Oracle January 2008 CPU",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27229",
          "name" : "27229",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-017A.html",
          "name" : "TA08-017A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0150",
          "name" : "ADV-2008-0150",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0180",
          "name" : "ADV-2008-0180",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Application Server 9.0.4.3 and 10.1.2.0.2; has unknown impact and local attack vectors, aka OCS01.  NOTE: Oracle has not disputed a reliable claim that this issue is related to WKSYS schema privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server_9i:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server_9i:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8dv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:11.1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.49:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T23:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0348",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8dv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.0.6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.49",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120058413923005&w=2",
          "name" : "SSRT061201",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28518",
          "name" : "28518",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28556",
          "name" : "28556",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019218",
          "name" : "1019218",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27229",
          "name" : "27229",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-017A.html",
          "name" : "TA08-017A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0150",
          "name" : "ADV-2008-0150",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0180",
          "name" : "ADV-2008-0180",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.18, 8.48.15, and 8.49.07 have unknown impact and remote attack vectors, aka (1) PSE01, (2) PSE03, and (3) PSE04."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8dv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:11.1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.49:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T23:00Z",
    "lastModifiedDate" : "2012-10-23T02:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0349",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8dv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.0.6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.49",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120058413923005&w=2",
          "name" : "SSRT061201",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28518",
          "name" : "28518",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28556",
          "name" : "28556",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019218",
          "name" : "1019218",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27229",
          "name" : "27229",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-017A.html",
          "name" : "TA08-017A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0150",
          "name" : "ADV-2008-0150",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0180",
          "name" : "ADV-2008-0180",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.15 and 8.49.07 has unknown impact and remote attack vectors, aka PSE02."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8dv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:11.1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.49:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-17T23:00Z",
    "lastModifiedDate" : "2012-10-23T02:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0350",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "evilsentinel",
            "product" : {
              "product_data" : [ {
                "product_name" : "evilsentinel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evilsentinel.altervista.org/forum/index.php?topic=49.0",
          "name" : "http://evilsentinel.altervista.org/forum/index.php?topic=49.0",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28427",
          "name" : "28427",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27227",
          "name" : "27227",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4884",
          "name" : "4884",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:evilsentinel:evilsentinel:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-18T00:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0351",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "evilsentinel",
            "product" : {
              "product_data" : [ {
                "product_name" : "evilsentinel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27227",
          "name" : "27227",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4884",
          "name" : "4884",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:evilsentinel:evilsentinel:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-18T00:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0352",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugzilla.kernel.org/show_bug.cgi?id=8450",
          "name" : "http://bugzilla.kernel.org/show_bug.cgi?id=8450",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.21.2",
          "name" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.21.2",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39643",
          "name" : "linux-kernel-ipv6-jumbogram-dos(39643)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4893",
          "name" : "4893",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving the Jumbo Payload hop-by-hop option (jumbogram)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:git1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:git2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:git3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:git4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:git5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:git6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:git7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-18T00:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0353",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php-residence",
            "product" : {
              "product_data" : [ {
                "product_name" : "php-residence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28516",
          "name" : "28516",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27320",
          "name" : "27320",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39739",
          "name" : "phpresidence-visualizza-sql-injection(39739)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4925",
          "name" : "4925",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in visualizza_tabelle.php in php-residence 0.7.2 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cognome_cerca parameter.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php-residence:php-residence:0.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php-residence:php-residence:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-18T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0354",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_sametime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/27942",
          "name" : "27942",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27316",
          "name" : "27316",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019224",
          "name" : "1019224",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0168",
          "name" : "ADV-2008-0168",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg21292938",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg21292938",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39726",
          "name" : "sametime-client-mouseover-xss(39726)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the chat client in IBM Lotus Sametime 7.5 and 7.5.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted message, which triggers code execution after a mouseover event initiated by the victim."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_sametime:7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_sametime:7.5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-18T22:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0355",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpecho_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpecho_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0-rc3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27326",
          "name" : "27326",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39741",
          "name" : "phpechocms-index-sql-injection(39741)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4929",
          "name" : "4929",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action, a different vector than CVE-2007-2866."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpecho_cms:phpecho_cms:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0-rc3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-18T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0356",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "citrix",
            "product" : {
              "product_data" : [ {
                "product_name" : "access_essentials",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "desktop_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "metaframe_presentation_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "presentation_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28508",
          "name" : "28508",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://support.citrix.com/article/CTX114487",
          "name" : "http://support.citrix.com/article/CTX114487",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/412228",
          "name" : "VU#412228",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486585/100/0/threaded",
          "name" : "20080117 ZDI-08-002: Citrix Presentation Server IMA Service Heap Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27329",
          "name" : "27329",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019231",
          "name" : "1019231",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0172",
          "name" : "ADV-2008-0172",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://zerodayinitiative.com/advisories/ZDI-08-002.html",
          "name" : "http://zerodayinitiative.com/advisories/ZDI-08-002.html",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code via an invalid size value in a packet to TCP port 2512 or 2513."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:citrix:access_essentials:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:citrix:desktop_server:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:citrix:metaframe_presentation_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:citrix:presentation_server:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-18T22:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0357",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "galaxyscripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "mini_file_host",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28504",
          "name" : "28504",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27327",
          "name" : "27327",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39799",
          "name" : "minifilehost-uploadphp-file-include(39799)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4930",
          "name" : "4930",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:galaxyscripts:mini_file_host:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-18T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0358",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pixelpost",
            "product" : {
              "product_data" : [ {
                "product_name" : "pixelpost",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28499",
          "name" : "28499",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.pixelpost.org/forum/showthread.php?t=7716",
          "name" : "http://www.pixelpost.org/forum/showthread.php?t=7716",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27242",
          "name" : "27242",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019238",
          "name" : "1019238",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39721",
          "name" : "pixelpost-indexphp-sql-injection(39721)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4924",
          "name" : "4924",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pixelpost:pixelpost:1.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-18T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0359",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "blog_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "blog_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2.1_c",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogcms.com/wiki/changelog",
          "name" : "http://blogcms.com/wiki/changelog",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=120049816924383&w=2",
          "name" : "20080116 [DSECRG-08-003] blogcms 4.2.1b Multiple Security Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28523",
          "name" : "28523",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27317",
          "name" : "27317",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39710",
          "name" : "blogcms-index-xss(39710)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4919",
          "name" : "4919",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin.php or (2) index.php in photo/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:blog_cms:blog_cms:4.2.1_c:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-18T22:00Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0360",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "blog_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "blog_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2.1_c",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogcms.com/wiki/changelog",
          "name" : "http://blogcms.com/wiki/changelog",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=120049816924383&w=2",
          "name" : "20080116 [DSECRG-08-003] blogcms 4.2.1b Multiple Security Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28523",
          "name" : "28523",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27317",
          "name" : "27317",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4919",
          "name" : "4919",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (1) the blogid parameter to index.php, (2) the user parameter to action.php, or (3) the field parameter to admin/plugins/table/index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:blog_cms:blog_cms:4.2.1_c:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-18T22:00Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0361",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "instituto_politicnico_nacional",
            "product" : {
              "product_data" : [ {
                "product_name" : "gradman",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28520",
          "name" : "28520",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3552",
          "name" : "3552",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486444/100/0/threaded",
          "name" : "20080116 Gradman <= 0.1.3 (agregar_info.php?tabla=) Local File Inclusion Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27324",
          "name" : "27324",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39732",
          "name" : "gradman-agregarinfo-file-include(39732)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4926",
          "name" : "4926",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:instituto_politicnico_nacional:gradman:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.1.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-18T22:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0362",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clever_copy",
            "product" : {
              "product_data" : [ {
                "product_name" : "clever_copy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28560",
          "name" : "28560",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3553",
          "name" : "3553",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486492/100/0/threaded",
          "name" : "20080117 Clever Copy <=3.0 Multiple Remote Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27335",
          "name" : "27335",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39747",
          "name" : "clevercopy-gallery-xss(39747)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in gallery.php in Clever Copy 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the album parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clever_copy:clever_copy:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-18T22:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0363",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clever_copy",
            "product" : {
              "product_data" : [ {
                "product_name" : "clever_copy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28560",
          "name" : "28560",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3553",
          "name" : "3553",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486492/100/0/threaded",
          "name" : "20080117 Clever Copy <=3.0 Multiple Remote Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27335",
          "name" : "27335",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39746",
          "name" : "clevercopy-postcomment-sql-injection(39746)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Clever Copy 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to postcomment.php and the (2) album parameter to gallery.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clever_copy:clever_copy:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-18T22:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0364",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bittorrent",
            "product" : {
              "product_data" : [ {
                "product_name" : "bittorrent",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "utorrent",
            "product" : {
              "product_data" : [ {
                "product_name" : "utorrent",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.5",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.8-alpha-7834",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/ruttorrent-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/ruttorrent-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://aluigi.org/poc/ruttorrent.zip",
          "name" : "http://aluigi.org/poc/ruttorrent.zip",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://download.utorrent.com/1.7.6/utorrent-1.7.6.txt",
          "name" : "http://download.utorrent.com/1.7.6/utorrent-1.7.6.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://forum.utorrent.com/viewtopic.php?id=29330",
          "name" : "http://forum.utorrent.com/viewtopic.php?id=29330",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28533",
          "name" : "28533",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28537",
          "name" : "28537",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3554",
          "name" : "3554",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486426/100/0/threaded",
          "name" : "20080116 Peers static overflow in BitTorrent 6.0 and uTorrent 1.7.5",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27321",
          "name" : "27321",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39719",
          "name" : "bittorrent-peers-bo(39719)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39720",
          "name" : "utorrent-peers-bo(39720)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; on Windows allows remote attackers to cause a denial of service (application crash) via a long Unicode string representing a client version identifier."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bittorrent:bittorrent:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.7.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.8-alpha-7834:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-18T23:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0365",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "core_security_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "core_force",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.95.167",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://force.coresecurity.com/index.php?module=articles&func=display&aid=32",
          "name" : "http://force.coresecurity.com/index.php?module=articles&func=display&aid=32",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3555",
          "name" : "3555",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.coresecurity.com/?action=item&id=2025",
          "name" : "http://www.coresecurity.com/?action=item&id=2025",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486513/100/0/threaded",
          "name" : "20080117 CORE-2007-1119: CORE FORCE Kernel Buffer Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27341",
          "name" : "27341",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019245",
          "name" : "1019245",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0242",
          "name" : "ADV-2008-0242",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39758",
          "name" : "coreforce-firewall-registry-bo(39758)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:core_security_technologies:core_force:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.95.167"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-18T23:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0366",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "core_security_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "core_force",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.95.167",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://force.coresecurity.com/index.php?module=articles&func=display&aid=32",
          "name" : "http://force.coresecurity.com/index.php?module=articles&func=display&aid=32",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3555",
          "name" : "3555",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.coresecurity.com/?action=item&id=2025",
          "name" : "http://www.coresecurity.com/?action=item&id=2025",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486513/100/0/threaded",
          "name" : "20080117 CORE-2007-1119: CORE FORCE Kernel Buffer Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27341",
          "name" : "27341",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019245",
          "name" : "1019245",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0242",
          "name" : "ADV-2008-0242",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CORE FORCE before 0.95.172 does not properly validate arguments to SSDT hook handler functions in the Registry module, which allows local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:core_security_technologies:core_force:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.95.167"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-18T23:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0367",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aviv.raffon.net/2008/01/02/YetAnotherDialogSpoofingFirefoxBasicAuthentication.aspx",
          "name" : "http://aviv.raffon.net/2008/01/02/YetAnotherDialogSpoofingFirefoxBasicAuthentication.aspx",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://aviv.raffon.net/2008/01/05/FirefoxDialogSpoofingFAQ.aspx",
          "name" : "http://aviv.raffon.net/2008/01/05/FirefoxDialogSpoofingFAQ.aspx",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://blog.mozilla.com/security/2008/01/04/basicauth-dialog-realm-value-spoofing/",
          "name" : "http://blog.mozilla.com/security/2008/01/04/basicauth-dialog-realm-value-spoofing/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485732/100/200/threaded",
          "name" : "20080103 Yet another Dialog Spoofing Vulnerability - Firefox Basic Authentication",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485738/100/200/threaded",
          "name" : "20080103 Re: [Full-disclosure] Yet another Dialog Spoofing Vulnerability - Firefox Basic Authentication",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27111",
          "name" : "27111",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=244273",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=244273",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing and spoofing attacks."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:3.0:beta2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-19T00:00Z",
    "lastModifiedDate" : "2018-10-26T14:19Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0368",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "informix_dynamic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=651",
          "name" : "20080131 IBM Informix Dynamic Server onedcu File Creation Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28534",
          "name" : "28534",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27328",
          "name" : "27328",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019237",
          "name" : "1019237",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0169",
          "name" : "ADV-2008-0169",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg1IC54307",
          "name" : "IC54307",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg27011556",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg27011556",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39751",
          "name" : "ibm-ids-onedcu-sqlidebug-unspecified(39751)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "onedcu in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allows local users to create arbitrary files via the Trace file argument."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:10.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-19T00:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0369",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "informix_dynamic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.00",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=650",
          "name" : "20080131 IBM Informix Dynamic Server SQLIDEBUG File Creation Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28534",
          "name" : "28534",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27328",
          "name" : "27328",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019237",
          "name" : "1019237",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0169",
          "name" : "ADV-2008-0169",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg1IC54309",
          "name" : "IC54309",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg27011556",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg27011556",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39751",
          "name" : "ibm-ids-onedcu-sqlidebug-unspecified(39751)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40009",
          "name" : "ibm-ids-sqlidebug-unspecified(40009)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified programs in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allow local users to create arbitrary files by specifying the target file in the SQLIDEBUG environment variable, whose ownership is changed to the user invoking the programs."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:10.00:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-19T00:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0370",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cpanel",
            "product" : {
              "product_data" : [ {
                "product_name" : "cpanel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.16",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aria-security.net/forum/showthread.php?p=1238",
          "name" : "http://aria-security.net/forum/showthread.php?p=1238",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28561",
          "name" : "28561",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3561",
          "name" : "3561",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486404/100/0/threaded",
          "name" : "20080116 cPanel Hosting Manager (dohtaccess.html)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27308",
          "name" : "27308",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in dohtaccess.html in cPanel before 11.17 build 19417 allows remote attackers to inject arbitrary web script or HTML via the rurl parameter.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:11.16:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0371",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "alilg",
            "product" : {
              "product_data" : [ {
                "product_name" : "alitalk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28515",
          "name" : "28515",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27315",
          "name" : "27315",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39733",
          "name" : "alitalk-receivertwo-sql-injection(39733)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39735",
          "name" : "alitalk-adminindex-sql-injection(39735)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39736",
          "name" : "alitalk-usercp-sql-injection(39736)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39745",
          "name" : "alitalk-index-sql-injection(39745)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4922",
          "name" : "4922",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in aliTalk 1.9.1.1, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via (1) the mohit parameter to (a) inc/receivertwo.php; and allow remote attackers to execute arbitrary SQL commands via (2) the id parameter to (b) inc/usercp.php, related to functionz/usercp.php; or (3) the username parameter to (c) admin/index.php, related to functionz/first_process.php, or (d) index.php.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alilg:alitalk:1.9.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0372",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "8e6",
            "product" : {
              "product_data" : [ {
                "product_name" : "r3000_internet_filter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.05.33",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "2.0.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28524",
          "name" : "28524",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3557",
          "name" : "3557",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486398/100/0/threaded",
          "name" : "20080116 8e6 Technologies R3000 Internet Filter Bypass by Request Split",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486770/100/0/threaded",
          "name" : "20080121 Re: 8e6 Technologies R3000 Internet Filter Bypass by Request Split",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27309",
          "name" : "27309",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39723",
          "name" : "r3000-urlfilter-security-bypass(39723)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "8e6 R3000 Internet Filter 2.0.05.33, and other versions before 2.0.11, allows remote attackers to bypass intended restrictions via a fragmented HTTP request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:8e6:r3000_internet_filter:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.05.33"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:8e6:r3000_internet_filter:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0373",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "f1_maxs_file_uploader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3572",
          "name" : "3572",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486335/100/0/threaded",
          "name" : "20080115 Max's File Uploader File Upload Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27285",
          "name" : "27285",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39740",
          "name" : "max-index-file-upload(39740)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unrestricted file upload vulnerability in PHP F1 Max's File Uploader allows remote attackers to upload and execute arbitrary PHP files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:f1_maxs_file_uploader:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0374",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oki_printing_solutions",
            "product" : {
              "product_data" : [ {
                "product_name" : "c5510_mfp_printer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "cu_h2.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "pu_01.03.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "system_fw_1.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "web_page_1.00",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-310"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28553",
          "name" : "28553",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3569",
          "name" : "3569",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html",
          "name" : "http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486511/100/0/threaded",
          "name" : "20080117 [CSNC] OKI C5510MFP Printer Password Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27339",
          "name" : "27339",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39775",
          "name" : "c5510mfp-configuration-info-disclosure(39775)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 sends the configuration of the printer in cleartext, which allows remote attackers to obtain the administrative password by connecting to TCP port 5548 or 7777."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:oki_printing_solutions:c5510_mfp_printer:cu_h2.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:oki_printing_solutions:c5510_mfp_printer:pu_01.03.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:oki_printing_solutions:c5510_mfp_printer:system_fw_1.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:oki_printing_solutions:c5510_mfp_printer:web_page_1.00:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0375",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oki_printing_solutions",
            "product" : {
              "product_data" : [ {
                "product_name" : "c5510_mfp_printer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          }, {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28553",
          "name" : "28553",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3569",
          "name" : "3569",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html",
          "name" : "http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486511/100/0/threaded",
          "name" : "20080117 [CSNC] OKI C5510MFP Printer Password Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27339",
          "name" : "27339",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39776",
          "name" : "c5510mfp-password-security-bypass(39776)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 allows remote attackers to set the password and obtain administrative access via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:oki_printing_solutions:c5510_mfp_printer:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0376",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "softpedia",
            "product" : {
              "product_data" : [ {
                "product_name" : "small_axe_weblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28568",
          "name" : "28568",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27345",
          "name" : "27345",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39765",
          "name" : "smallaxeweblog-linkbar-file-include(39765)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4937",
          "name" : "4937",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfile parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:softpedia:small_axe_weblog:0.3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0377",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "news",
            "product" : {
              "product_data" : [ {
                "product_name" : "micronews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3556",
          "name" : "3556",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486349/100/0/threaded",
          "name" : "20080115 MicroNews Admin Direct Access vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27288",
          "name" : "27288",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39702",
          "name" : "micronews-admin-authentication-bypass(39702)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "MicroNews allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:news:micronews:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0378",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nec",
            "product" : {
              "product_data" : [ {
                "product_name" : "sockscap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.40_051231",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3560",
          "name" : "3560",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486632/100/0/threaded",
          "name" : "20080118 SocksCap Stack Overflow (<= 2.40-051231)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27357",
          "name" : "27357",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39781",
          "name" : "sockscap-hostname-bo(39781)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in SocksCap 2.40-051231 and earlier, when \"Resolve all names remotely\" is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hostname."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nec:sockscap:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.40_051231"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0379",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "businessobjects",
            "product" : {
              "product_data" : [ {
                "product_name" : "crystal_reports_xi",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "activex",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "enterprise_tree_control",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27333",
          "name" : "27333",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019239",
          "name" : "1019239",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39743",
          "name" : "crystalreports-enterprisetree-bo(39743)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4931",
          "name" : "4931",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SelectedSession method, which triggers a buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:businessobjects:crystal_reports_xi:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:activex:enterprise_tree_control:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0380",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "digital_data_communications",
            "product" : {
              "product_data" : [ {
                "product_name" : "rtspvapgdecoder.dll",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.0.29",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28492",
          "name" : "28492",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27337",
          "name" : "27337",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0182",
          "name" : "ADV-2008-0182",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4932",
          "name" : "4932",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:digital_data_communications:rtspvapgdecoder.dll:1.1.0.29:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0381",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mahara",
            "product" : {
              "product_data" : [ {
                "product_name" : "mahara",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28484",
          "name" : "28484",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27348",
          "name" : "27348",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://eduforge.org/frs/shownotes.php?release_id=342",
          "name" : "https://eduforge.org/frs/shownotes.php?release_id=342",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Mahara before 0.9.1 has unknown impact and remote attack vectors, probably related to cross-site scripting (XSS) in uploaded files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.9.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2008-09-05T21:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0382",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybulletinboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybulletinboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_pr2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28509",
          "name" : "28509",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3559",
          "name" : "3559",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486434/100/0/threaded",
          "name" : "20080116 [waraxe-2008-SA#061] - Remote Code Execution in MyBB 1.2.10",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27322",
          "name" : "27322",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4927",
          "name" : "4927",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4928",
          "name" : "4928",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_pr2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.2.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0383",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://community.mybboard.net/showthread.php?tid=27227",
          "name" : "http://community.mybboard.net/showthread.php?tid=27227",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28509",
          "name" : "28509",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3558",
          "name" : "3558",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486433/100/0/threaded",
          "name" : "20080116 [waraxe-2008-SA#062] - Multiple Sql Injections in MyBB 1.2.10",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27323",
          "name" : "27323",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.waraxe.us/advisory-62.html",
          "name" : "http://www.waraxe.us/advisory-62.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39728",
          "name" : "mybb-moderationphp-sql-injection(39728)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39729",
          "name" : "mybb-usergroups-sql-injection(39729)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in MyBB 1.2.10 and earlier allow remote moderators and administrators to execute arbitrary SQL commands via (1) the mergepost parameter in a do_mergeposts action, (2) rid parameter in an allreports action, or (3) threads parameter in a do_multimovethreads action to (a) moderation.php; or (4) gid parameter to (b) admin/usergroups.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0384",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openbsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "openbsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=openbsd-security-announce&m=120007327504064",
          "name" : "[openbsd-security-announce] 20080111 errata 005 for OpenBSD 4.2: local users can provoke a kernel panic",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28473",
          "name" : "28473",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.openbsd.org/errata42.html#005_ifrtlabel",
          "name" : "[4.2] 20080111 005: RELIABILITY FIX: January 11, 2008",
          "refsource" : "OPENBSD",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27252",
          "name" : "27252",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019188",
          "name" : "1019188",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4935",
          "name" : "4935",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an interface that does not have a route label, which triggers a NULL pointer dereference when the return value from the rtlabel_id2name function is not checked."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:openbsd:openbsd:4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-22T20:00Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0385",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "urulu",
            "product" : {
              "product_data" : [ {
                "product_name" : "urulu",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29162",
          "name" : "29162",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3707",
          "name" : "3707",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.csnc.ch/misc/files/advisories/CVE-2008-0385.txt",
          "name" : "http://www.csnc.ch/misc/files/advisories/CVE-2008-0385.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488909/100/0/threaded",
          "name" : "20080228 Urulu 2.1 Blind SQL Injection Vulnerability (CVE-2008-0385)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28032",
          "name" : "28032",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in server/widgetallocator.php in Urulu 2.1 allows remote attackers to execute arbitrary SQL commands via the connectionId parameter to index.php with (1) statprt/js/request or (2) dyn/js/request in the PATH_INFO."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:urulu:urulu:2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-29T19:44Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0386",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gentoo",
            "product" : {
              "product_data" : [ {
                "product_name" : "xdg-utils",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=207331",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=207331",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00008.html",
          "name" : "SUSE-SR:2008:004",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28638",
          "name" : "28638",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28728",
          "name" : "28728",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29048",
          "name" : "29048",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200801-21.xml",
          "name" : "GLSA-200801-21",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-email.in?r1=1.24&r2=1.25",
          "name" : "http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-email.in?r1=1.24&r2=1.25",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-email.in?view=log",
          "name" : "http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-email.in?view=log",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-email?r1=1.36&r2=1.37",
          "name" : "http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-email?r1=1.36&r2=1.37",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-open.in?r1=1.17&r2=1.18",
          "name" : "http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-open.in?r1=1.17&r2=1.18",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-open?r1=1.32&r2=1.33",
          "name" : "http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-open?r1=1.32&r2=1.33",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-open?view=log",
          "name" : "http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-open?view=log",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:031",
          "name" : "MDVSA-2008:031",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27528",
          "name" : "27528",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019284",
          "name" : "1019284",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0342",
          "name" : "ADV-2008-0342",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=429513",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=429513",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Xdg-utils 1.0.2 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URL argument to (1) xdg-open or (2) xdg-email."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2007.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2007.1:*:x86-64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2008.0:*:x86-64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:gentoo:xdg-utils:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "1.0.2"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-04T23:00Z",
    "lastModifiedDate" : "2011-03-08T03:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0387",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "firebirdsql",
            "product" : {
              "product_data" : [ {
                "product_name" : "firebird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.3",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.4306",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2.4731",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3.4870",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.4.4910",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.12748",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1.12855",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29203",
          "name" : "29203",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29501",
          "name" : "29501",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-02.xml",
          "name" : "GLSA-200803-02",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3580",
          "name" : "3580",
          "refsource" : "SREASON",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=9028&release_id=570800",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=9028&release_id=570800",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://tracker.firebirdsql.org/browse/CORE-1681",
          "name" : "http://tracker.firebirdsql.org/browse/CORE-1681",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.coresecurity.com/?action=item&id=2095",
          "name" : "http://www.coresecurity.com/?action=item&id=2095",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1529",
          "name" : "DSA-1529",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487173/100/0/threaded",
          "name" : "20080128 CORE-2007-1219: Firebird Remote Memory Corruption",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27403",
          "name" : "27403",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39996",
          "name" : "firebird-xdrprotocol-integer-overflow(39996)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.5",
          "versionEndExcluding" : "1.5.6"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.0.0",
          "versionEndExcluding" : "2.0.4"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:firebirdsql:firebird:2.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T02:00Z",
    "lastModifiedDate" : "2018-10-26T14:19Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0388",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wp_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2008-02/0272.html",
          "name" : "20080216 WordPress forumaction (PAGE_id)(user)SQL Injectio",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/52211",
          "name" : "52211",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28567",
          "name" : "28567",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://weblogtoolscollection.com/archives/2008/01/21/wp-forum-plugin-security-bulletin/",
          "name" : "http://weblogtoolscollection.com/archives/2008/01/21/wp-forum-plugin-security-bulletin/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27362",
          "name" : "27362",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0235",
          "name" : "ADV-2008-0235",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39800",
          "name" : "wpforum-index-sql-injection(39800)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4939",
          "name" : "4939",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user parameter in a showprofile action to the default URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wp_forum:1.7.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0389",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1.17",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.14",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28576",
          "name" : "28576",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29687",
          "name" : "29687",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27371",
          "name" : "27371",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019251",
          "name" : "1019251",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019894",
          "name" : "1019894",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0219",
          "name" : "ADV-2008-0219",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1133",
          "name" : "ADV-2008-1133",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg24018067",
          "name" : "PK52059",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg27006879#51118",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg27006879#51118",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39808",
          "name" : "websphere-serveservlets-unspecified(39808)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through 6.1.0.14, and 5.1.1.x before 5.1.1.18 has unknown impact and attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:5.1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:5.1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:5.1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:5.1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:5.1.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:5.1.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:5.1.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:5.1.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:5.1.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:5.1.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:5.1.1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:5.1.1.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:5.1.1.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:5.1.1.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1.1.17"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:fp17:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0.2.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0.2.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0.2.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0.2.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0.2.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0.2.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0.2.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.0.2.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.1.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:6.1.14:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T02:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0390",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "auracms",
            "product" : {
              "product_data" : [ {
                "product_name" : "auracms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.62",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mod_block_statistik",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27342",
          "name" : "27342",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39777",
          "name" : "auracms-stat-code-execution(39777)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4933",
          "name" : "4933",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via the X-Forwarded-For HTTP header in a stat action to index.php, and execute online.db.txt via a certain request to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:auracms:auracms:1.62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:auracms:mod_block_statistik:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0391",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "alilg",
            "product" : {
              "product_data" : [ {
                "product_name" : "alitalk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27315",
          "name" : "27315",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4922",
          "name" : "4922",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a modified lilil parameter, in conjunction with the ubild and pa parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alilg:alitalk:1.9.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0392",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "visual_basic",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28563",
          "name" : "28563",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27349",
          "name" : "27349",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019258",
          "name" : "1019258",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0195",
          "name" : "ADV-2008-0195",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39773",
          "name" : "visualbasic-enterprise-dsr-bo(39773)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4938",
          "name" : "4938",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file with a long (1) ConnectionName or (2) CommandName line."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visual_basic:6.0:sp6:enterprise:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-23T03:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0393",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gradman",
            "product" : {
              "product_data" : [ {
                "product_name" : "gradman",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28520",
          "name" : "28520",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27343",
          "name" : "27343",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39768",
          "name" : "gradman-info-file-include(39768)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4936",
          "name" : "4936",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter, a different vector than CVE-2008-0361."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gradman:gradman:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.1.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T03:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0394",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "citadel",
            "product" : {
              "product_data" : [ {
                "product_name" : "smtp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28590",
          "name" : "28590",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.milw0rm.com/sploits/2008-vs-GNU-citadel.tar.gz",
          "name" : "http://www.milw0rm.com/sploits/2008-vs-GNU-citadel.tar.gz",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27376",
          "name" : "27376",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019255",
          "name" : "1019255",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0252",
          "name" : "ADV-2008-0252",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39807",
          "name" : "citadel-makeuserkey-bo(39807)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4949",
          "name" : "4949",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which is not properly handled by the makeuserkey function.  NOTE: some of these details were obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:citadel:smtp:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T12:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0395",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kayako",
            "product" : {
              "product_data" : [ {
                "product_name" : "supportsuite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.11.01",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28613",
          "name" : "28613",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3573",
          "name" : "3573",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486762/100/0/threaded",
          "name" : "20080121 [waraxe-2008-SA#063] - Information Leakage in Kayako SupportSuite 3.11.01",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.waraxe.us/advisory-63.html",
          "name" : "http://www.waraxe.us/advisory-63.html",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml/index.php, which prints the contents of the $_SERVER superglobal."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kayako:supportsuite:3.11.01:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T12:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0396",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bitdefender",
            "product" : {
              "product_data" : [ {
                "product_name" : "update_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://oliver.greyhat.de/2008/01/19/bitdefender-unauthorized-remote-file-access-vulnerability/",
          "name" : "http://oliver.greyhat.de/2008/01/19/bitdefender-unauthorized-remote-file-access-vulnerability/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28578",
          "name" : "28578",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3568",
          "name" : "3568",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.oliverkarow.de/research/bitdefender.txt",
          "name" : "http://www.oliverkarow.de/research/bitdefender.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486701/100/0/threaded",
          "name" : "20080119 BitDefender Update Server - Unauthorized Remote File Access Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27358",
          "name" : "27358",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0213",
          "name" : "ADV-2008-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39802",
          "name" : "bitdefender-http-server-directory-traversal(39802)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Enterprise Manager (BDEM), allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bitdefender:update_server:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T12:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0397",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aflog.org",
            "product" : {
              "product_data" : [ {
                "product_name" : "aflog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.01",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28594",
          "name" : "28594",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27398",
          "name" : "27398",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0255",
          "name" : "ADV-2008-0255",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39825",
          "name" : "aflog-comments-sql-injection(39825)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4958",
          "name" : "4958",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in aflog 1.01, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to comments.php and (2) an unspecified parameter to view.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aflog.org:aflog:1.01:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T12:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0398",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aflog",
            "product" : {
              "product_data" : [ {
                "product_name" : "aflog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.01",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28594",
          "name" : "28594",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27398",
          "name" : "27398",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0255",
          "name" : "ADV-2008-0255",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4958",
          "name" : "4958",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in aflog 1.01, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment form."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aflog:aflog:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.01"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-23T12:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0399",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "toshiba",
            "product" : {
              "product_data" : [ {
                "product_name" : "surveillix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://retrogod.altervista.org/rgod_toshiba_control.html",
          "name" : "http://retrogod.altervista.org/rgod_toshiba_control.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28557",
          "name" : "28557",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27360",
          "name" : "27360",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0214",
          "name" : "ADV-2008-0214",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39792",
          "name" : "toshiba-recordsend-bo(39792)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4946",
          "name" : "4946",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort and (2) SetIpAddress methods."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:toshiba:surveillix:1.0.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-23T12:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0400",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "modern",
            "product" : {
              "product_data" : [ {
                "product_name" : "modern",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "singapore",
            "product" : {
              "product_data" : [ {
                "product_name" : "singapore",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.10.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28573",
          "name" : "28573",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://trew.icenetx.net/toolz/advisory-singapore-modern-template.txt",
          "name" : "http://trew.icenetx.net/toolz/advisory-singapore-modern-template.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27382",
          "name" : "27382",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0234",
          "name" : "ADV-2008-0234",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in header.tpl.php in the modern template for Singapore 0.10.1 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter to default.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:modern:modern:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:singapore:singapore:0.10.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-23T12:00Z",
    "lastModifiedDate" : "2011-03-08T03:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0401",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tivoli_provisioning_manager_os_deployment",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.0.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=647",
          "name" : "20080122 IBM Tivoli PMfOSD HTTP Request Method Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28604",
          "name" : "28604",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/158609",
          "name" : "VU#158609",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27387",
          "name" : "27387",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019249",
          "name" : "1019249",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0239",
          "name" : "ADV-2008-0239",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg24018010",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg24018010",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39819",
          "name" : "tivoli-provisioning-http-unspecified(39819)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an HTTP request with a long method string to port 443/tcp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_provisioning_manager_os_deployment:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1.0.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T12:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0402",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_business_modeler",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.2_1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28586",
          "name" : "28586",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27389",
          "name" : "27389",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019252",
          "name" : "1019252",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0254",
          "name" : "ADV-2008-0254",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg24018060",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg24018060",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg24018061",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg24018061",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www-1.ibm.com/support/search.wss?rs=0&q=JR28175&apar=only",
          "name" : "JR28175",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39830",
          "name" : "websphere-repository-weak-security(39830)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's owning group."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_business_modeler:6.0.2_1:*:advanced:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_business_modeler:6.0.2_1:*:basic:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T12:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0403",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "belkin",
            "product" : {
              "product_data" : [ {
                "product_name" : "f5d9230-4",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28554",
          "name" : "28554",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3566",
          "name" : "3566",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486748/100/0/threaded",
          "name" : "20080119 Belkin Wireless G Plus MIMO Router F5D9230-4 Authentication Bypass Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27359",
          "name" : "27359",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0215",
          "name" : "ADV-2008-0215",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39793",
          "name" : "belkin-savecfgfile-authentication-bypass(39793)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4941",
          "name" : "4941",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to read and modify configuration via a direct request to SaveCfgFile.cgi."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:belkin:f5d9230-4:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T12:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0404",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mantis",
            "product" : {
              "product_data" : [ {
                "product_name" : "mantis",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.4a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.0",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.1.0a1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28577",
          "name" : "28577",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28591",
          "name" : "28591",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=569765",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=569765",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27367",
          "name" : "27367",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0232",
          "name" : "ADV-2008-0232",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=429552",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=429552",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39801",
          "name" : "mantis-mostactive-xss(39801)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00676.html",
          "name" : "FEDORA-2008-0796",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00734.html",
          "name" : "FEDORA-2008-0856",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the \"Most active bugs\" summary."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.16.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.16.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.4a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0a3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.1.0a1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-23T12:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0405",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hfs",
            "product" : {
              "product_data" : [ {
                "product_name" : "http_file_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2b",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28631",
          "name" : "28631",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3581",
          "name" : "3581",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.rejetto.com/hfs/?f=wn",
          "name" : "http://www.rejetto.com/hfs/?f=wn",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486873/100/0/threaded",
          "name" : "20080123 Syhunt: HFS (HTTP File Server) Log Arbitrary File/Directory Manipulation and Denial-of-Service Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27423",
          "name" : "27423",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.syhunt.com/advisories/hfs-1-log.txt",
          "name" : "http://www.syhunt.com/advisories/hfs-1-log.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.syhunt.com/advisories/hfshack.txt",
          "name" : "http://www.syhunt.com/advisories/hfshack.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39873",
          "name" : "hfs-unspecified-command-execution(39873)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesting the / URI; and (3) append arbitrary data to a file via a .. (dot dot) in an account name, when requesting a URI composed of a \"/?%0a\" sequence followed by the data."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hfs:http_file_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.2b"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T00:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0406",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hfs",
            "product" : {
              "product_data" : [ {
                "product_name" : "http_file_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2b",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28631",
          "name" : "28631",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3581",
          "name" : "3581",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.rejetto.com/hfs/?f=wn",
          "name" : "http://www.rejetto.com/hfs/?f=wn",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486873/100/0/threaded",
          "name" : "20080123 Syhunt: HFS (HTTP File Server) Log Arbitrary File/Directory Manipulation and Denial-of-Service Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27423",
          "name" : "27423",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.syhunt.com/advisories/hfs-1-log.txt",
          "name" : "http://www.syhunt.com/advisories/hfs-1-log.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.syhunt.com/advisories/hfshack.txt",
          "name" : "http://www.syhunt.com/advisories/hfshack.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39875",
          "name" : "hfs-filename-dos(39875)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash) via a long account name."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hfs:http_file_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.2b"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T00:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0407",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hfs",
            "product" : {
              "product_data" : [ {
                "product_name" : "http_file_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2b",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28631",
          "name" : "28631",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3582",
          "name" : "3582",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.rejetto.com/hfs/?f=wn",
          "name" : "http://www.rejetto.com/hfs/?f=wn",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486874/100/0/threaded",
          "name" : "20080123 Syhunt: HFS (HTTP File Server) Username Spoofing and Log Forging/Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27423",
          "name" : "27423",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.syhunt.com/advisories/hfs-1-username.txt",
          "name" : "http://www.syhunt.com/advisories/hfs-1-username.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.syhunt.com/advisories/hfshack.txt",
          "name" : "http://www.syhunt.com/advisories/hfshack.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39877",
          "name" : "hfs-username-spoofing(39877)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hfs:http_file_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.2b"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T00:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0408",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hfs",
            "product" : {
              "product_data" : [ {
                "product_name" : "http_file_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2b",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28631",
          "name" : "28631",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3582",
          "name" : "3582",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.rejetto.com/hfs/?f=wn",
          "name" : "http://www.rejetto.com/hfs/?f=wn",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486874/100/0/threaded",
          "name" : "20080123 Syhunt: HFS (HTTP File Server) Username Spoofing and Log Forging/Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27423",
          "name" : "27423",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.syhunt.com/advisories/hfs-1-username.txt",
          "name" : "http://www.syhunt.com/advisories/hfs-1-username.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.syhunt.com/advisories/hfshack.txt",
          "name" : "http://www.syhunt.com/advisories/hfshack.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39876",
          "name" : "hfs-unspecified-log-injection(39876)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text during HTTP Basic Authentication."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hfs:http_file_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.2b"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T00:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0409",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hfs",
            "product" : {
              "product_data" : [ {
                "product_name" : "http_file_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2b",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28631",
          "name" : "28631",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3583",
          "name" : "3583",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.rejetto.com/hfs/?f=wn",
          "name" : "http://www.rejetto.com/hfs/?f=wn",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486872/100/0/threaded",
          "name" : "20080123 Syhunt: HFS (HTTP File Server) Template Cross-Site Scripting and Information Disclosure Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27423",
          "name" : "27423",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.syhunt.com/advisories/hfs-1-template.txt",
          "name" : "http://www.syhunt.com/advisories/hfs-1-template.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.syhunt.com/advisories/hfshack.txt",
          "name" : "http://www.syhunt.com/advisories/hfshack.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39870",
          "name" : "hfs-host-xss(39870)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in HTTP File Server (HFS) before 2.2c allows remote attackers to inject arbitrary web script or HTML via the userinfo subcomponent of a URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hfs:http_file_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.2b"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-29T00:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0410",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hfs",
            "product" : {
              "product_data" : [ {
                "product_name" : "http_file_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2b",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28631",
          "name" : "28631",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3583",
          "name" : "3583",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.rejetto.com/hfs/?f=wn",
          "name" : "http://www.rejetto.com/hfs/?f=wn",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486872/100/0/threaded",
          "name" : "20080123 Syhunt: HFS (HTTP File Server) Template Cross-Site Scripting and Information Disclosure Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27423",
          "name" : "27423",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.syhunt.com/advisories/hfs-1-template.txt",
          "name" : "http://www.syhunt.com/advisories/hfs-1-template.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.syhunt.com/advisories/hfshack.txt",
          "name" : "http://www.syhunt.com/advisories/hfshack.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39871",
          "name" : "hfs-sendhfsidentifier-info-disclosure(39871)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as <id>%version%</id> in HTTP Basic Authentication instead of a username and password, as demonstrated by placing this id element in the userinfo subcomponent of a URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hfs:http_file_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.2b"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T00:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0411",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ghostscript",
            "product" : {
              "product_data" : [ {
                "product_name" : "ghostscript",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.61",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00009.html",
          "name" : "SUSE-SA:2008:010",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://scary.beasts.org/security/CESA-2008-001.html",
          "name" : "http://scary.beasts.org/security/CESA-2008-001.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/29101",
          "name" : "29101",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29103",
          "name" : "29103",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29112",
          "name" : "29112",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29135",
          "name" : "29135",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29147",
          "name" : "29147",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29154",
          "name" : "29154",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29169",
          "name" : "29169",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29196",
          "name" : "29196",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29314",
          "name" : "29314",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29768",
          "name" : "29768",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.370633",
          "name" : "SSA:2008-062-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0082",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0082",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1510",
          "name" : "DSA-1510",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200803-14.xml",
          "name" : "GLSA-200803-14",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:055",
          "name" : "MDVSA-2008:055",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0155.html",
          "name" : "RHSA-2008:0155",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488932/100/0/threaded",
          "name" : "20080228 rPSA-2008-0082-1 espgs",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488946/100/0/threaded",
          "name" : "20080228 Ghostscript buffer overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28017",
          "name" : "28017",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019511",
          "name" : "1019511",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-599-1",
          "name" : "USN-599-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0693/references",
          "name" : "ADV-2008-0693",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2217",
          "name" : "https://issues.rpath.com/browse/RPL-2217",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9557",
          "name" : "oval:org.mitre.oval:def:9557",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00085.html",
          "name" : "FEDORA-2008-1998",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:alpha:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:amd64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:arm:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:hppa:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:ia-32:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:ia-64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:m68k:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:mips:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:mipsel:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:ppc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:s-390:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:sparc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:alpha:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:amd64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:arm:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:hppa:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:ia-32:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:ia-64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:m68k:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:mips:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:mipsel:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:powerpc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:s-390:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:sparc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2007:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2007.0_x86_64:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2007.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2007.1:*:x86-64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2008.0:*:x86-64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrakesoft_corporate_server:3.0_x86_64:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrakesoft_corporate_server:4.0_x86_64:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:desktop:3.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:desktop:4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:5:*:server:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:as_3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:as_4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:es_3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:es_4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:ws_3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:ws_4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:5:*:client:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop_workstation:5:*:client:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:rpath:rpath_linux:1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:novell_linux_pos:9:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:open_suse:10.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:open_suse:10.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.0:*:enterprise_server:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10:sp1:enterprise_desktop:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10:sp1:enterprise_server:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10.1:*:ppc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10.1:*:x86:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10.1:*:x86_64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_open_enterprise_server:0:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ghostscript:ghostscript:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "8.61"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:alpha:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:amd64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:arm:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:hppa:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:ia-32:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:ia-64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:m68k:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:mips:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:mipsel:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:ppc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:s-390:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:sparc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:alpha:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:amd64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:arm:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:hppa:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:ia-32:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:ia-64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:m68k:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:mips:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:mipsel:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:powerpc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:s-390:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:sparc:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ghostscript:ghostscript:0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ghostscript:ghostscript:8.0.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ghostscript:ghostscript:8.15:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-28T21:44Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0412",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.7",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://browser.netscape.com/releasenotes/",
          "name" : "http://browser.netscape.com/releasenotes/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html",
          "name" : "SUSE-SA:2008:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28754",
          "name" : "28754",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28758",
          "name" : "28758",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28766",
          "name" : "28766",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28808",
          "name" : "28808",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28815",
          "name" : "28815",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28818",
          "name" : "28818",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28839",
          "name" : "28839",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28864",
          "name" : "28864",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28865",
          "name" : "28865",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28877",
          "name" : "28877",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28879",
          "name" : "28879",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28924",
          "name" : "28924",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28939",
          "name" : "28939",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28958",
          "name" : "28958",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29049",
          "name" : "29049",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29086",
          "name" : "29086",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29098",
          "name" : "29098",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29164",
          "name" : "29164",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29167",
          "name" : "29167",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29211",
          "name" : "29211",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29567",
          "name" : "29567",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30327",
          "name" : "30327",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30620",
          "name" : "30620",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31043",
          "name" : "31043",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.445399",
          "name" : "SSA:2008-061-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1",
          "name" : "238492",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1",
          "name" : "239546",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "name" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0093",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0093",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1484",
          "name" : "DSA-1484",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1485",
          "name" : "DSA-1485",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1489",
          "name" : "DSA-1489",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1506",
          "name" : "DSA-1506",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml",
          "name" : "GLSA-200805-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:048",
          "name" : "MDVSA-2008:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:062",
          "name" : "MDVSA-2008:062",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-01.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0103.html",
          "name" : "RHSA-2008:0103",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0104.html",
          "name" : "RHSA-2008:0104",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0105.html",
          "name" : "RHSA-2008:0105",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487826/100/0/threaded",
          "name" : "20080209 rPSA-2008-0051-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488002/100/0/threaded",
          "name" : "20080212 FLEA-2008-0001-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488971/100/0/threaded",
          "name" : "20080229 rPSA-2008-0093-1 thunderbird",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27683",
          "name" : "27683",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019320",
          "name" : "1019320",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-576-1",
          "name" : "USN-576-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-582-1",
          "name" : "USN-582-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-582-2",
          "name" : "USN-582-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0453/references",
          "name" : "ADV-2008-0453",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0454/references",
          "name" : "ADV-2008-0454",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0627/references",
          "name" : "ADV-2008-0627",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1793/references",
          "name" : "ADV-2008-1793",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2091/references",
          "name" : "ADV-2008-2091",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/buglist.cgi?bug_id=398088,393141,364801,346405,396613,394337,406290",
          "name" : "https://bugzilla.mozilla.org/buglist.cgi?bug_id=398088,393141,364801,346405,396613,394337,406290",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1995",
          "name" : "https://issues.rpath.com/browse/RPL-1995",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10573",
          "name" : "oval:org.mitre.oval:def:10573",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html",
          "name" : "FEDORA-2008-1435",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html",
          "name" : "FEDORA-2008-1459",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html",
          "name" : "FEDORA-2008-1535",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html",
          "name" : "FEDORA-2008-2060",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html",
          "name" : "FEDORA-2008-2118",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The browser engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to the (1) nsTableFrame::GetFrameAtOrBefore, (2) nsAccessibilityService::GetAccessible, (3) nsBindingManager::GetNestedInsertionPoint, (4) nsXBLPrototypeBinding::AttributeChanged, (5) nsColumnSetFrame::GetContentInsertionFrame, and (6) nsLineLayout::TrimTrailingWhiteSpaceIn methods, and other vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.7"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-08T22:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0413",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.7",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://browser.netscape.com/releasenotes/",
          "name" : "http://browser.netscape.com/releasenotes/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html",
          "name" : "SUSE-SA:2008:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28754",
          "name" : "28754",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28758",
          "name" : "28758",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28766",
          "name" : "28766",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28808",
          "name" : "28808",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28815",
          "name" : "28815",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28818",
          "name" : "28818",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28839",
          "name" : "28839",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28864",
          "name" : "28864",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28865",
          "name" : "28865",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28877",
          "name" : "28877",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28879",
          "name" : "28879",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28924",
          "name" : "28924",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28939",
          "name" : "28939",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28958",
          "name" : "28958",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29049",
          "name" : "29049",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29086",
          "name" : "29086",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29098",
          "name" : "29098",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29164",
          "name" : "29164",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29167",
          "name" : "29167",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29211",
          "name" : "29211",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30327",
          "name" : "30327",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30620",
          "name" : "30620",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31043",
          "name" : "31043",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.445399",
          "name" : "SSA:2008-061-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1",
          "name" : "238492",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1",
          "name" : "239546",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0093",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0093",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1484",
          "name" : "DSA-1484",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1485",
          "name" : "DSA-1485",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1489",
          "name" : "DSA-1489",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1506",
          "name" : "DSA-1506",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml",
          "name" : "GLSA-200805-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:048",
          "name" : "MDVSA-2008:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:062",
          "name" : "MDVSA-2008:062",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-01.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0103.html",
          "name" : "RHSA-2008:0103",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0104.html",
          "name" : "RHSA-2008:0104",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0105.html",
          "name" : "RHSA-2008:0105",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487826/100/0/threaded",
          "name" : "20080209 rPSA-2008-0051-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488002/100/0/threaded",
          "name" : "20080212 FLEA-2008-0001-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488971/100/0/threaded",
          "name" : "20080229 rPSA-2008-0093-1 thunderbird",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27683",
          "name" : "27683",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019321",
          "name" : "1019321",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-576-1",
          "name" : "USN-576-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-582-1",
          "name" : "USN-582-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-582-2",
          "name" : "USN-582-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0453/references",
          "name" : "ADV-2008-0453",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0454/references",
          "name" : "ADV-2008-0454",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0627/references",
          "name" : "ADV-2008-0627",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1793/references",
          "name" : "ADV-2008-1793",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2091/references",
          "name" : "ADV-2008-2091",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/buglist.cgi?bug_id=407720,390597,373344,398085,406572,391028,406036,402087",
          "name" : "https://bugzilla.mozilla.org/buglist.cgi?bug_id=407720,390597,373344,398085,406572,391028,406036,402087",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1995",
          "name" : "https://issues.rpath.com/browse/RPL-1995",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10385",
          "name" : "oval:org.mitre.oval:def:10385",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html",
          "name" : "FEDORA-2008-1435",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html",
          "name" : "FEDORA-2008-1459",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html",
          "name" : "FEDORA-2008-1535",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html",
          "name" : "FEDORA-2008-2060",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html",
          "name" : "FEDORA-2008-2118",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The JavaScript engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via (1) a large switch statement, (2) certain uses of watch and eval, (3) certain uses of the mousedown event listener, and other vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.7"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-08T22:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0414",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://browser.netscape.com/releasenotes/",
          "name" : "http://browser.netscape.com/releasenotes/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html",
          "name" : "SUSE-SA:2008:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28758",
          "name" : "28758",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28815",
          "name" : "28815",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28839",
          "name" : "28839",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28864",
          "name" : "28864",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28865",
          "name" : "28865",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28877",
          "name" : "28877",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28879",
          "name" : "28879",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28924",
          "name" : "28924",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28939",
          "name" : "28939",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28958",
          "name" : "28958",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29049",
          "name" : "29049",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29086",
          "name" : "29086",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29567",
          "name" : "29567",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30327",
          "name" : "30327",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30620",
          "name" : "30620",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1",
          "name" : "238492",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "name" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1484",
          "name" : "DSA-1484",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1485",
          "name" : "DSA-1485",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1489",
          "name" : "DSA-1489",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1506",
          "name" : "DSA-1506",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml",
          "name" : "GLSA-200805-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:048",
          "name" : "MDVSA-2008:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-02.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-02.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487826/100/0/threaded",
          "name" : "20080209 rPSA-2008-0051-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488002/100/0/threaded",
          "name" : "20080212 FLEA-2008-0001-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27683",
          "name" : "27683",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019330",
          "name" : "1019330",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-576-1",
          "name" : "USN-576-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0453/references",
          "name" : "ADV-2008-0453",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0627/references",
          "name" : "ADV-2008-0627",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1793/references",
          "name" : "ADV-2008-1793",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/buglist.cgi?bug_id=404451,408034,404391,405299",
          "name" : "https://bugzilla.mozilla.org/buglist.cgi?bug_id=404451,408034,404391,405299",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html",
          "name" : "FEDORA-2008-1435",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html",
          "name" : "FEDORA-2008-1459",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html",
          "name" : "FEDORA-2008-1535",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to trick the user into uploading arbitrary files via label tags that shift focus to a file input field, aka \"focus spoofing.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-08T22:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0415",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.7",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://browser.netscape.com/releasenotes/",
          "name" : "http://browser.netscape.com/releasenotes/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html",
          "name" : "SUSE-SA:2008:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28754",
          "name" : "28754",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28758",
          "name" : "28758",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28766",
          "name" : "28766",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28808",
          "name" : "28808",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28815",
          "name" : "28815",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28818",
          "name" : "28818",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28839",
          "name" : "28839",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28864",
          "name" : "28864",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28865",
          "name" : "28865",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28877",
          "name" : "28877",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28879",
          "name" : "28879",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28924",
          "name" : "28924",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28939",
          "name" : "28939",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28958",
          "name" : "28958",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29049",
          "name" : "29049",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29086",
          "name" : "29086",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29098",
          "name" : "29098",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29164",
          "name" : "29164",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29167",
          "name" : "29167",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29211",
          "name" : "29211",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29567",
          "name" : "29567",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30327",
          "name" : "30327",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30620",
          "name" : "30620",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31043",
          "name" : "31043",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.445399",
          "name" : "SSA:2008-061-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1",
          "name" : "238492",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1",
          "name" : "239546",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "name" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0093",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0093",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1484",
          "name" : "DSA-1484",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1485",
          "name" : "DSA-1485",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1489",
          "name" : "DSA-1489",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1506",
          "name" : "DSA-1506",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml",
          "name" : "GLSA-200805-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:048",
          "name" : "MDVSA-2008:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:062",
          "name" : "MDVSA-2008:062",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-03.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-03.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0103.html",
          "name" : "RHSA-2008:0103",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0104.html",
          "name" : "RHSA-2008:0104",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0105.html",
          "name" : "RHSA-2008:0105",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487826/100/0/threaded",
          "name" : "20080209 rPSA-2008-0051-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488002/100/0/threaded",
          "name" : "20080212 FLEA-2008-0001-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488971/100/0/threaded",
          "name" : "20080229 rPSA-2008-0093-1 thunderbird",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27683",
          "name" : "27683",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019327",
          "name" : "1019327",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-576-1",
          "name" : "USN-576-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-582-1",
          "name" : "USN-582-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-582-2",
          "name" : "USN-582-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0453/references",
          "name" : "ADV-2008-0453",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0454/references",
          "name" : "ADV-2008-0454",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0627/references",
          "name" : "ADV-2008-0627",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1793/references",
          "name" : "ADV-2008-1793",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2091/references",
          "name" : "ADV-2008-2091",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/buglist.cgi?bug_id=386695,393761,393762,399298,407289,372075,363597",
          "name" : "https://bugzilla.mozilla.org/buglist.cgi?bug_id=386695,393761,393762,399298,407289,372075,363597",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1995",
          "name" : "https://issues.rpath.com/browse/RPL-1995",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9897",
          "name" : "oval:org.mitre.oval:def:9897",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html",
          "name" : "FEDORA-2008-1435",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html",
          "name" : "FEDORA-2008-1459",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html",
          "name" : "FEDORA-2008-1535",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html",
          "name" : "FEDORA-2008-2060",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html",
          "name" : "FEDORA-2008-2118",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka \"JavaScript privilege escalation bugs.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.7"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-08T22:00Z",
    "lastModifiedDate" : "2018-10-15T21:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0416",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.7",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jvn.jp/en/jp/JVN21563357/index.html",
          "name" : "JVN#21563357",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000021.html",
          "name" : "JVNDB-2008-000021",
          "refsource" : "JVNDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28839",
          "name" : "28839",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28864",
          "name" : "28864",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28865",
          "name" : "28865",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28879",
          "name" : "28879",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29541",
          "name" : "29541",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30327",
          "name" : "30327",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30620",
          "name" : "30620",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31043",
          "name" : "31043",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1",
          "name" : "238492",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1",
          "name" : "239546",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1484",
          "name" : "DSA-1484",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1485",
          "name" : "DSA-1485",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1489",
          "name" : "DSA-1489",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml",
          "name" : "GLSA-200805-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-13.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-13.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29303",
          "name" : "29303",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.turbolinux.com/security/2008/TLSA-2008-9.txt",
          "name" : "TLSA-2008-9",
          "refsource" : "TURBO",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-592-1",
          "name" : "USN-592-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-087A.html",
          "name" : "TA08-087A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1793/references",
          "name" : "ADV-2008-1793",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2091/references",
          "name" : "ADV-2008-2091",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.mozilla.org/buglist.cgi?bug_id=404252,381412,407161",
          "name" : "https://bugzilla.mozilla.org/buglist.cgi?bug_id=404252,381412,407161",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40488",
          "name" : "firefox-character-encoding-xss(40488)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/576-1/",
          "name" : "USN-576-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox  before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote attackers to inject arbitrary web script or HTML via certain character encodings, including (1) a backspace character that is treated as whitespace, (2) 0x80 with Shift_JIS encoding, and (3) \"zero-length non-ASCII sequences\" in certain Asian character sets."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.7"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T03:00Z",
    "lastModifiedDate" : "2018-10-03T21:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0417",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://browser.netscape.com/releasenotes/",
          "name" : "http://browser.netscape.com/releasenotes/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html",
          "name" : "SUSE-SA:2008:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28766",
          "name" : "28766",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28818",
          "name" : "28818",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28839",
          "name" : "28839",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28864",
          "name" : "28864",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28865",
          "name" : "28865",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28877",
          "name" : "28877",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28879",
          "name" : "28879",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28924",
          "name" : "28924",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28939",
          "name" : "28939",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28958",
          "name" : "28958",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29086",
          "name" : "29086",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29567",
          "name" : "29567",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30327",
          "name" : "30327",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30620",
          "name" : "30620",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1",
          "name" : "238492",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "name" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1484",
          "name" : "DSA-1484",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1485",
          "name" : "DSA-1485",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1489",
          "name" : "DSA-1489",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1506",
          "name" : "DSA-1506",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml",
          "name" : "GLSA-200805-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:048",
          "name" : "MDVSA-2008:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-04.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-04.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0103.html",
          "name" : "RHSA-2008:0103",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0104.html",
          "name" : "RHSA-2008:0104",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487826/100/0/threaded",
          "name" : "20080209 rPSA-2008-0051-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488002/100/0/threaded",
          "name" : "20080212 FLEA-2008-0001-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27683",
          "name" : "27683",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019334",
          "name" : "1019334",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-576-1",
          "name" : "USN-576-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0453/references",
          "name" : "ADV-2008-0453",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0627/references",
          "name" : "ADV-2008-0627",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1793/references",
          "name" : "ADV-2008-1793",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=394610",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=394610",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11154",
          "name" : "oval:org.mitre.oval:def:11154",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html",
          "name" : "FEDORA-2008-1435",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html",
          "name" : "FEDORA-2008-1459",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html",
          "name" : "FEDORA-2008-1535",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CRLF injection vulnerability in Mozilla Firefox before 2.0.0.12 allows remote user-assisted web sites to corrupt the user's password store via newlines that are not properly handled when the user saves a password."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-08T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0418",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.7",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://browser.netscape.com/releasenotes/",
          "name" : "http://browser.netscape.com/releasenotes/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html",
          "name" : "SUSE-SA:2008:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28622/",
          "name" : "28622",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28754",
          "name" : "28754",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28766",
          "name" : "28766",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28808",
          "name" : "28808",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28815",
          "name" : "28815",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28818",
          "name" : "28818",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28839",
          "name" : "28839",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28864",
          "name" : "28864",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28865",
          "name" : "28865",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28877",
          "name" : "28877",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28879",
          "name" : "28879",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28924",
          "name" : "28924",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28939",
          "name" : "28939",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28958",
          "name" : "28958",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29049",
          "name" : "29049",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29086",
          "name" : "29086",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29098",
          "name" : "29098",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29164",
          "name" : "29164",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29167",
          "name" : "29167",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29211",
          "name" : "29211",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29567",
          "name" : "29567",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30327",
          "name" : "30327",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30620",
          "name" : "30620",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31043",
          "name" : "31043",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.445399",
          "name" : "SSA:2008-061-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1",
          "name" : "238492",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1",
          "name" : "239546",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "name" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0093",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0093",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1484",
          "name" : "DSA-1484",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1485",
          "name" : "DSA-1485",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1489",
          "name" : "DSA-1489",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1506",
          "name" : "DSA-1506",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml",
          "name" : "GLSA-200805-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/",
          "name" : "http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/309608",
          "name" : "VU#309608",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:048",
          "name" : "MDVSA-2008:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:062",
          "name" : "MDVSA-2008:062",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-05.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-05.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0103.html",
          "name" : "RHSA-2008:0103",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0104.html",
          "name" : "RHSA-2008:0104",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0105.html",
          "name" : "RHSA-2008:0105",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487826/100/0/threaded",
          "name" : "20080209 rPSA-2008-0051-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488002/100/0/threaded",
          "name" : "20080212 FLEA-2008-0001-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488971/100/0/threaded",
          "name" : "20080229 rPSA-2008-0093-1 thunderbird",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27406",
          "name" : "27406",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019329",
          "name" : "1019329",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-576-1",
          "name" : "USN-576-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-582-1",
          "name" : "USN-582-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-582-2",
          "name" : "USN-582-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0263",
          "name" : "ADV-2008-0263",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0453/references",
          "name" : "ADV-2008-0453",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0454/references",
          "name" : "ADV-2008-0454",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0627/references",
          "name" : "ADV-2008-0627",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1793/references",
          "name" : "ADV-2008-1793",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2091/references",
          "name" : "ADV-2008-2091",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1995",
          "name" : "https://issues.rpath.com/browse/RPL-1995",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10705",
          "name" : "oval:org.mitre.oval:def:10705",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html",
          "name" : "FEDORA-2008-1435",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html",
          "name" : "FEDORA-2008-1459",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html",
          "name" : "FEDORA-2008-1535",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html",
          "name" : "FEDORA-2008-2060",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html",
          "name" : "FEDORA-2008-2118",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using \"flat\" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome: URI scheme, as demonstrated by stealing session information from sessionstore.js."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.7"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-08T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0419",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://browser.netscape.com/releasenotes/",
          "name" : "http://browser.netscape.com/releasenotes/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html",
          "name" : "SUSE-SA:2008:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28754",
          "name" : "28754",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28758",
          "name" : "28758",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28766",
          "name" : "28766",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28808",
          "name" : "28808",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28815",
          "name" : "28815",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28818",
          "name" : "28818",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28839",
          "name" : "28839",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28864",
          "name" : "28864",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28865",
          "name" : "28865",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28877",
          "name" : "28877",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28879",
          "name" : "28879",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28924",
          "name" : "28924",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28939",
          "name" : "28939",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28958",
          "name" : "28958",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29049",
          "name" : "29049",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29086",
          "name" : "29086",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29164",
          "name" : "29164",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29167",
          "name" : "29167",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29567",
          "name" : "29567",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30327",
          "name" : "30327",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30620",
          "name" : "30620",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1",
          "name" : "238492",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "name" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0093",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0093",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1484",
          "name" : "DSA-1484",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1485",
          "name" : "DSA-1485",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1489",
          "name" : "DSA-1489",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1506",
          "name" : "DSA-1506",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml",
          "name" : "GLSA-200805-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/879056",
          "name" : "VU#879056",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:048",
          "name" : "MDVSA-2008:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-06.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-06.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0103.html",
          "name" : "RHSA-2008:0103",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0104.html",
          "name" : "RHSA-2008:0104",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0105.html",
          "name" : "RHSA-2008:0105",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487826/100/0/threaded",
          "name" : "20080209 rPSA-2008-0051-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488002/100/0/threaded",
          "name" : "20080212 FLEA-2008-0001-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488971/100/0/threaded",
          "name" : "20080229 rPSA-2008-0093-1 thunderbird",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27683",
          "name" : "27683",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019328",
          "name" : "1019328",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-576-1",
          "name" : "USN-576-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0453/references",
          "name" : "ADV-2008-0453",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0627/references",
          "name" : "ADV-2008-0627",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1793/references",
          "name" : "ADV-2008-1793",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=400556",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=400556",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1995",
          "name" : "https://issues.rpath.com/browse/RPL-1995",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11652",
          "name" : "oval:org.mitre.oval:def:11652",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html",
          "name" : "FEDORA-2008-1435",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html",
          "name" : "FEDORA-2008-1459",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html",
          "name" : "FEDORA-2008-1535",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html",
          "name" : "FEDORA-2008-2060",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html",
          "name" : "FEDORA-2008-2118",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows remote attackers to steal navigation history and cause a denial of service (crash) via images in a page that uses designMode frames, which triggers memory corruption related to resize handles."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-08T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0420",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.7",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://browser.netscape.com/releasenotes/",
          "name" : "http://browser.netscape.com/releasenotes/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28758",
          "name" : "28758",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28839",
          "name" : "28839",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29049",
          "name" : "29049",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29098",
          "name" : "29098",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29167",
          "name" : "29167",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30327",
          "name" : "30327",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30620",
          "name" : "30620",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019434",
          "name" : "1019434",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1",
          "name" : "238492",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml",
          "name" : "GLSA-200805-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:048",
          "name" : "MDVSA-2008:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-07.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-07.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488264/100/0/threaded",
          "name" : "20080216 [HISPASEC] FireFox 2.0.0.11 and Opera 9.50 beta Remote Memory Information Leak, FireFox 2.0.0.11 Remote Denial of Service",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27826",
          "name" : "27826",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-582-1",
          "name" : "USN-582-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-582-2",
          "name" : "USN-582-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0627/references",
          "name" : "ADV-2008-0627",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1793/references",
          "name" : "ADV-2008-1793",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=408076",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=408076",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40491",
          "name" : "firefox-bmp-information-disclosure(40491)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40606",
          "name" : "firefox-bmp-dos(40606)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10119",
          "name" : "oval:org.mitre.oval:def:10119",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/576-1/",
          "name" : "USN-576-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html",
          "name" : "FEDORA-2008-2060",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html",
          "name" : "FEDORA-2008-2118",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as demonstrated using a CANVAS element; or cause a denial of service (application crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read. NOTE: the initial public reports stated that this affected Firefox in Ubuntu 6.06 through 7.10."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0:preview_release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.7"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:2.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:2.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:2.0.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:2.0.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:2.0.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T03:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0421",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "invision_power_services",
            "product" : {
              "product_data" : [ {
                "product_name" : "invision_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://www.exploit-db.com/exploits/4966",
          "name" : "4966",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in a rate command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_gallery:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T21:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0422",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "boastmachine",
            "product" : {
              "product_data" : [ {
                "product_name" : "boastmachine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3563",
          "name" : "3563",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486737/100/0/threaded",
          "name" : "20080121 boastMachine <=3.1 SQL Injection Vulnerbility",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/498521/100/0/threaded",
          "name" : "20081120 boastMachine v3.1 Remote Sql Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27369",
          "name" : "27369",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/32379",
          "name" : "32379",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0227",
          "name" : "ADV-2008-0227",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39813",
          "name" : "boastmachine-mail-sql-injection(39813)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4952",
          "name" : "4952",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:boastmachine:boastmachine:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0423",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lama",
            "product" : {
              "product_data" : [ {
                "product_name" : "lama_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28442",
          "name" : "28442",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27380",
          "name" : "27380",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0230",
          "name" : "ADV-2008-0230",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39821",
          "name" : "lamasoftware-myconf-file-include(39821)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4955",
          "name" : "4955",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MY_CONF[classRoot] parameter to (1) inc.steps.access_error.php, (2) inc.steps.check_login.php, or (3) inc.steps.init_system.php in admin/functions/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lama:lama_software:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0424",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mooseguy_blog_system",
            "product" : {
              "product_data" : [ {
                "product_name" : "mgbs",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27377",
          "name" : "27377",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0226",
          "name" : "ADV-2008-0226",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39816",
          "name" : "mooseguy-blog-sql-injection(39816)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4951",
          "name" : "4951",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in blog.php in Mooseguy Blog System (MGBS) 1.0 allows remote attackers to execute arbitrary SQL commands via the month parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mooseguy_blog_system:mgbs:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0425",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "frimousse",
            "product" : {
              "product_data" : [ {
                "product_name" : "frimousse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27385",
          "name" : "27385",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0216",
          "name" : "ADV-2008-0216",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39797",
          "name" : "frimousse-explorerdir-directory-traversal(39797)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4943",
          "name" : "4943",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary files and list arbitrary directories via a full pathname in the name parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:frimousse:frimousse:0.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0426",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pacercms",
            "product" : {
              "product_data" : [ {
                "product_name" : "pacercms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://pacercms.sourceforge.net/index.php/2008/01/21/pacercms-061-streamlines-code-base-addresses-security-issue/",
          "name" : "http://pacercms.sourceforge.net/index.php/2008/01/21/pacercms-061-streamlines-code-base-addresses-security-issue/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28605",
          "name" : "28605",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486796/100/0/threaded",
          "name" : "20080122 PacerCMS Multiple Vulnerabilities (XSS/SQL)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27386",
          "name" : "27386",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39832",
          "name" : "pacercms-submit-xss(39832)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PacerCMS before 0.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) headline, or (3) text field in a message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pacercms:pacercms:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.6.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0427",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bloo",
            "product" : {
              "product_data" : [ {
                "product_name" : "bloofoxcms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugreport.ir/?/27",
          "name" : "http://bugreport.ir/?/27",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=120093005310107&w=2",
          "name" : "20080120 Bloofox CMS SQL Injection (Authentication bypass) , Source code",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28415",
          "name" : "28415",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486714/100/0/threaded",
          "name" : "20080120 Bloofox CMS SQL Injection (Authentication bypass) , Source codedisclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27361",
          "name" : "27361",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0218",
          "name" : "ADV-2008-0218",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39795",
          "name" : "bloofoxcms-file-directory-traversal(39795)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4945",
          "name" : "4945",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bloo:bloofoxcms:0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0428",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bloofoxcms",
            "product" : {
              "product_data" : [ {
                "product_name" : "bloofoxcms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugreport.ir/?/27",
          "name" : "http://bugreport.ir/?/27",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=120093005310107&w=2",
          "name" : "20080120 Bloofox CMS SQL Injection (Authentication bypass) , Source code",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28415",
          "name" : "28415",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486714/100/0/threaded",
          "name" : "20080120 Bloofox CMS SQL Injection (Authentication bypass) , Source codedisclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27361",
          "name" : "27361",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0218",
          "name" : "ADV-2008-0218",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39794",
          "name" : "bloofoxcms-index-sql-injection(39794)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4945",
          "name" : "4945",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in the login function in system/class_permissions.php in bloofoxCMS 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bloofoxcms:bloofoxcms:0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0429",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "alstrasoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "forum_pay_per_post_exchange",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28581",
          "name" : "28581",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27381",
          "name" : "27381",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0231",
          "name" : "ADV-2008-0231",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39820",
          "name" : "alstrasoft-indexphp-sql-injection(39820)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4956",
          "name" : "4956",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/6401",
          "name" : "6401",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a forum_catview action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alstrasoft:forum_pay_per_post_exchange:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0430",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "360_web_manager",
            "product" : {
              "product_data" : [ {
                "product_name" : "360_web_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27364",
          "name" : "27364",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0217",
          "name" : "ADV-2008-0217",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39796",
          "name" : "360web-form-sql-injection(39796)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4944",
          "name" : "4944",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in form.php in 360 Web Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the IDFM parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:360_web_manager:360_web_manager:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0431",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "idmos",
            "product" : {
              "product_data" : [ {
                "product_name" : "idmos_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28436",
          "name" : "28436",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27379",
          "name" : "27379",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0229",
          "name" : "ADV-2008-0229",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39823",
          "name" : "idmos-download-directory-traversal(39823)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4954",
          "name" : "4954",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in administrator/download.php in IDMOS (aka Phoenix) 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:idmos:idmos_cms:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0432",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "agares_media",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpautovideo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.21",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28580",
          "name" : "28580",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3567",
          "name" : "3567",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486591/100/0/threaded",
          "name" : "20080118 Agares PhpAutoVideo 2.21(XSS/RFI) Multiple Remote Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27346",
          "name" : "27346",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0225",
          "name" : "ADV-2008-0225",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39771",
          "name" : "phpautovideo-index-xss(39771)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in phpAutoVideo 2.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:agares_media:phpautovideo:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.21"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0433",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "agares_media",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpautovideo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.21",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28580",
          "name" : "28580",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3567",
          "name" : "3567",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486591/100/0/threaded",
          "name" : "20080118 Agares PhpAutoVideo 2.21(XSS/RFI) Multiple Remote Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27346",
          "name" : "27346",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0225",
          "name" : "ADV-2008-0225",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39770",
          "name" : "phpautovideo-sidebar-file-include(39770)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loadpage parameter, a different vector than CVE-2007-6614."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:agares_media:phpautovideo:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.21"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0434",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gecad_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "axigen_mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059788.html",
          "name" : "20080120 AXIGEN 5.0.x AXIMilter Format String Exploit",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28562",
          "name" : "28562",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3570",
          "name" : "3570",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486722/100/0/threaded",
          "name" : "20080120 AXIGEN 5.0.x AXIMilter Format String Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27363",
          "name" : "27363",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0237",
          "name" : "ADV-2008-0237",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39803",
          "name" : "axigen-aximilter-format-string(39803)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4947",
          "name" : "4947",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbitrary code via format string specifiers in the CNHO command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gecad_technologies:axigen_mail_server:5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0435",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ozjournals",
            "product" : {
              "product_data" : [ {
                "product_name" : "ozjournals",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28582",
          "name" : "28582",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27375",
          "name" : "27375",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0228",
          "name" : "ADV-2008-0228",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39815",
          "name" : "ozjournals-id-directory-traversal(39815)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4953",
          "name" : "4953",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in index.php in OZJournals 2.1.1 allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the id parameter in a printpreview action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ozjournals:ozjournals:2.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0436",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pd9_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "megabbs",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.14b",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3565",
          "name" : "3565",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486723/100/0/threaded",
          "name" : "20080120 MegaBBS ASP Forum Cross-Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27368",
          "name" : "27368",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39812",
          "name" : "megabbs-upload-xss(39812)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in profile-upload/upload.asp in PD9 Software MegaBBS 1.5.14b allows remote attackers to inject arbitrary web script or HTML via the target parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pd9_software:megabbs:1.5.14b:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0437",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "virtual_rooms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0.100",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "activex",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=120098751528333&w=2",
          "name" : "20080122 HP Virtual Rooms WebHPVCInstall Control Multiple Buffer Overflows",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28595",
          "name" : "28595",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27384",
          "name" : "27384",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0236",
          "name" : "ADV-2008-0236",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39836",
          "name" : "hpvirtualrooms-hpvirtualrooms14-activex-bo(39836)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4959",
          "name" : "4959",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1) AuthenticationURL, (2) PortalAPIURL, or (3) cabroot property value.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:virtual_rooms:1.0.0.100:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:activex:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0438",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "novemberborn",
            "product" : {
              "product_data" : [ {
                "product_name" : "sifr",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://novemberborn.net/sifr/2.0.3",
          "name" : "http://novemberborn.net/sifr/2.0.3",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/41006",
          "name" : "41006",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3571",
          "name" : "3571",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.procheckup.com/Vulnerability_PR07-38.php",
          "name" : "http://www.procheckup.com/Vulnerability_PR07-38.php",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486787/100/0/threaded",
          "name" : "20080122 PR07-38: XSS on sIFR",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486829/100/0/threaded",
          "name" : "20080122 Re: PR07-38: XSS on sIFR",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487585/100/200/threaded",
          "name" : "20080205 Re: PR07-38: XSS on sIFR",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27394",
          "name" : "27394",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39835",
          "name" : "sifr-fontname-xss(39835)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the font rendering functionality in Novemberborn sIFR 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the txt parameter to a Flash (SWF) file, as demonstrated by fonts/FuturaLt.swf."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novemberborn:sifr:2.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0439",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "deluxebb",
            "product" : {
              "product_data" : [ {
                "product_name" : "deluxebb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3564",
          "name" : "3564",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486804/100/0/threaded",
          "name" : "20080122 DeluxeBB 1.1 XSS Vulnerabilitie",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27401",
          "name" : "27401",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39829",
          "name" : "deluxbb-attachmentsheader-xss(39829)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in templates/default/admincp/attachments_header.php in DeluxeBB 1.1 allows remote attackers to inject arbitrary web script or HTML via the lang_listofmatches parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:deluxebb:deluxebb:1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-23T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0440",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "alstrasoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "forum_pay_per_post_exchange",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-255"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://www.exploit-db.com/exploits/4956",
          "name" : "4956",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "AlstraSoft Forum Pay Per Post Exchange 2.0 stores passwords in cleartext, which makes it easier for attackers to access user accounts."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alstrasoft:forum_pay_per_post_exchange:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-23T23:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0441",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tivoli_business_service_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28603",
          "name" : "28603",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27388",
          "name" : "27388",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019250",
          "name" : "1019250",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0240",
          "name" : "ADV-2008-0240",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg24017939",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg24017939",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39822",
          "name" : "tbsm-reconfig-information-disclosure(39822)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Tivoli Business Service Manager (TBSM) 4.1.1 stores passwords in cleartext (1) after external authentication, which triggers writing the password to SM_server.log; and (2) after a reconfig action; which allows local users to obtain sensitive information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_business_service_manager:4.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T00:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0442",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "small_axe_solutions",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28568",
          "name" : "28568",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27383",
          "name" : "27383",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the ffile parameter, a different vector than CVE-2008-0376.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:small_axe_solutions:weblog:0.3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T00:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0443",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lycos",
            "product" : {
              "product_data" : [ {
                "product_name" : "fileuploader.dll",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28599",
          "name" : "28599",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27411",
          "name" : "27411",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0253",
          "name" : "ADV-2008-0253",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39849",
          "name" : "lycosfileuploader-fileuploader-activex-bo(39849)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4967",
          "name" : "4967",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUploader Module allows remote attackers to execute arbitrary code via a long HandwriterFilename property value.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lycos:fileuploader.dll:2.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T00:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0444",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "elog",
            "product" : {
              "product_data" : [ {
                "product_name" : "elog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://midas.psi.ch/elog/download/ChangeLog",
          "name" : "http://midas.psi.ch/elog/download/ChangeLog",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/41681",
          "name" : "41681",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28589",
          "name" : "28589",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27399",
          "name" : "27399",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0265",
          "name" : "ADV-2008-0265",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39828",
          "name" : "elog-subtext-xss(39828)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via subtext parameter to unspecified components."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.6.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-25T00:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0445",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "elog",
            "product" : {
              "product_data" : [ {
                "product_name" : "elog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28589",
          "name" : "28589",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27399",
          "name" : "27399",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0265",
          "name" : "ADV-2008-0265",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39824",
          "name" : "elog-elogd-logbook-dos(39824)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The replace_inline_img function in elogd in Electronic Logbook (ELOG) before 2.7.1 allows remote attackers to cause a denial of service (infinite loop) via crafted logbook entries.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:1.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elog:elog:2.6.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T00:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0446",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "julian_pawlowski",
            "product" : {
              "product_data" : [ {
                "product_name" : "lulieblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27416",
          "name" : "27416",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39854",
          "name" : "lulieblog-voircom-sql-injection(39854)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4969",
          "name" : "4969",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in voircom.php in LulieBlog 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:julian_pawlowski:lulieblog:1.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T00:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0447",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "foojan",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_weblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27415",
          "name" : "27415",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39855",
          "name" : "foojanwms-index-sql-injection(39855)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4968",
          "name" : "4968",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in Foojan WMS PHP Weblog 1.0 allows remote attackers to execute arbitrary SQL commands via the story parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:foojan:php_weblog:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T00:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0448",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cybergl_dev_team",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpsearch",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120093067011293&w=2",
          "name" : "20080120 Php Search Remote Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39805",
          "name" : "phpsearch-classhttpretriever-file-include(39805)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in utils/class_HTTPRetriever.php in phpSearch allows remote attackers to execute arbitrary PHP code via a URL in the libcurlemuinc parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cybergl_dev_team:phpsearch:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T00:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0449",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rocksalt_international",
            "product" : {
              "product_data" : [ {
                "product_name" : "vp_asp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.50",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27347",
          "name" : "27347",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39811",
          "name" : "vpasp-paypalresult-sql-injection(39811)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in paypalresult.asp in VP-ASP Shopping Cart 6.50 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rocksalt_international:vp_asp:4.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rocksalt_international:vp_asp:4.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rocksalt_international:vp_asp:5.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rocksalt_international:vp_asp:5.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rocksalt_international:vp_asp:6.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rocksalt_international:vp_asp:6.50:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T00:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0450",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "blog_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "blog_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2.1_c",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3576",
          "name" : "3576",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486743/100/0/threaded",
          "name" : "20080121 BLOG:CMS 4.2.1.c (DIR_PLUGINS) Multiple Remote File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in BLOG:CMS 4.2.1.c allow remote attackers to execute arbitrary PHP code via a URL in the (1) DIR_PLUGINS parameter to (a) index.php, and the (2) DIR_LIBS parameter to (b) media.php and (c) xmlrpc/server.php in admin/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:blog_cms:blog_cms:4.2.1_c:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T00:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0451",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pacercms",
            "product" : {
              "product_data" : [ {
                "product_name" : "pacercms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://pacercms.sourceforge.net/index.php/2008/01/21/pacercms-061-streamlines-code-base-addresses-security-issue/",
          "name" : "http://pacercms.sourceforge.net/index.php/2008/01/21/pacercms-061-streamlines-code-base-addresses-security-issue/",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3574",
          "name" : "3574",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486796/100/0/threaded",
          "name" : "20080122 PacerCMS Multiple Vulnerabilities (XSS/SQL)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27397",
          "name" : "27397",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39833",
          "name" : "pacercms-articleedit-sql-injection(39833)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in PacerCMS 0.6 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) siteadmin/article-edit.php; and unspecified parameters to (2) submitted-edit.php, (3) page-edit.php, (4) section-edit.php, (5) staff-edit.php, and (6) staff-access.php in siteadmin/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pacercms:pacercms:0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T00:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0452",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "siteman",
            "product" : {
              "product_data" : [ {
                "product_name" : "siteman",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27422",
          "name" : "27422",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4973",
          "name" : "4973",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in articles.php in Siteman 1.1.9 allows remote attackers to read arbitrary files via directory traversal sequences in the cat parameter in a viewart action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:siteman:siteman:1.1.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T00:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0453",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "easysitenetwork",
            "product" : {
              "product_data" : [ {
                "product_name" : "recipe_website_script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27405",
          "name" : "27405",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39853",
          "name" : "easysitenetworkrecipe-list-sql-injection(39853)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4960",
          "name" : "4960",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in list.php in Easysitenetwork Recipe allows remote attackers to execute arbitrary SQL commands via the categoryid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:easysitenetwork:recipe_website_script:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T00:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0454",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "skype_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "skype",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.0.244",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0337.html",
          "name" : "20080117 Skype videomood XSS",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0363.html",
          "name" : "20080117 Re: Skype videomood XSS",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://aviv.raffon.net/2008/01/17/SkypeCrosszoneScriptingVulnerability.aspx",
          "name" : "http://aviv.raffon.net/2008/01/17/SkypeCrosszoneScriptingVulnerability.aspx",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://share.skype.com/sites/security/2008/01/skype_cross_zone_scripting_vul.html",
          "name" : "http://share.skype.com/sites/security/2008/01/skype_cross_zone_scripting_vul.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://skype.com/security/skype-sb-2008-001.html",
          "name" : "http://skype.com/security/skype-sb-2008-001.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://skype.com/security/skype-sb-2008-001-update1.html",
          "name" : "http://skype.com/security/skype-sb-2008-001-update1.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.critical.lt/?opinions/show/1470",
          "name" : "http://www.critical.lt/?opinions/show/1470",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.gnucitizen.org/blog/vulnerabilities-in-skype",
          "name" : "http://www.gnucitizen.org/blog/vulnerabilities-in-skype",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/248184",
          "name" : "VU#248184",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486512/100/0/threaded",
          "name" : "20080117 RE: Skype videomood XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27338",
          "name" : "27338",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0194",
          "name" : "ADV-2008-0194",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39754",
          "name" : "skype-addvideotochat-code-execution(39754)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the \"Add video to chat\" dialog, aka \"videomood XSS.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:skype_technologies:skype:3.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:skype_technologies:skype:3.6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:skype_technologies:skype:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "3.6.0.244"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-25T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0455",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.49",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.55",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.56",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.58",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.59",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://rhn.redhat.com/errata/RHSA-2012-1591.html",
          "name" : "RHSA-2012:1591",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2012-1592.html",
          "name" : "RHSA-2012:1592",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2012-1594.html",
          "name" : "RHSA-2012:1594",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2013-0130.html",
          "name" : "RHSA-2013:0130",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29348",
          "name" : "29348",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/51607",
          "name" : "51607",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-19.xml",
          "name" : "GLSA-200803-19",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3575",
          "name" : "3575",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019256",
          "name" : "1019256",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.mindedsecurity.com/MSA01150108.html",
          "name" : "http://www.mindedsecurity.com/MSA01150108.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486847/100/0/threaded",
          "name" : "20080122 Apache mod_negotiation Xss and Http Response Splitting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27409",
          "name" : "27409",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39867",
          "name" : "apache-modnegotiation-xss(39867)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20190815 svn commit: r1048743 [4/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20190815 svn commit: r1048742 [4/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20190815 svn commit: r1048743 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20190815 svn commit: r1048742 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20200401 svn commit: r1058586 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20200401 svn commit: r1058586 [4/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20200401 svn commit: r1058587 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) \"406 Not Acceptable\" or (2) \"300 Multiple Choices\" HTTP response when the extension is omitted in a request for the file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:1.3.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.28:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.38:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.43:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.44:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.45:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.46:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.49:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.55:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.56:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.58:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.59:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.0.61:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.2.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-25T01:00Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0456",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.49",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.55",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.56",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.57",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.58",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.59",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2009/May/msg00002.html",
          "name" : "APPLE-SA-2009-05-12",
          "refsource" : "APPLE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2013-0130.html",
          "name" : "RHSA-2013:0130",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29348",
          "name" : "29348",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/35074",
          "name" : "35074",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-19.xml",
          "name" : "GLSA-200803-19",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3575",
          "name" : "3575",
          "refsource" : "SREASON",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019256",
          "name" : "1019256",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://support.apple.com/kb/HT3549",
          "name" : "http://support.apple.com/kb/HT3549",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mindedsecurity.com/MSA01150108.html",
          "name" : "http://www.mindedsecurity.com/MSA01150108.html",
          "refsource" : "MISC",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486847/100/0/threaded",
          "name" : "20080122 Apache mod_negotiation Xss and Http Response Splitting",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27409",
          "name" : "27409",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA09-133A.html",
          "name" : "TA09-133A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2009/1297",
          "name" : "ADV-2009-1297",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39893",
          "name" : "apache-modnegotiation-response-splitting(39893)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20190815 svn commit: r1048743 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20190815 svn commit: r1048742 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20200401 svn commit: r1058586 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20200401 svn commit: r1058587 [3/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) \"406 Not Acceptable\" or (2) \"300 Multiple Choices\" HTTP response when the extension is omitted in a request for the file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.3.0",
          "versionEndIncluding" : "1.3.39"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.0.0",
          "versionEndIncluding" : "2.0.61"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.2.0",
          "versionEndIncluding" : "2.2.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-25T01:00Z",
    "lastModifiedDate" : "2019-08-15T09:15Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0457",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "backupexec_system_recovery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.01",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28787",
          "name" : "28787",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://seer.entsupport.symantec.com/docs/297171.htm",
          "name" : "http://seer.entsupport.symantec.com/docs/297171.htm",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487688/100/0/threaded",
          "name" : "20080206 ZDI-08-003: Symantec Backup Exec Remote File Upload Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27487",
          "name" : "27487",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019303",
          "name" : "1019303",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.symantec.com/avcenter/security/Content/2008.02.04.html",
          "name" : "http://www.symantec.com/avcenter/security/Content/2008.02.04.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0413",
          "name" : "ADV-2008-0413",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-003.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-003.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5078",
          "name" : "5078",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:backupexec_system_recovery:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:backupexec_system_recovery:7.01:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0458",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "slaed",
            "product" : {
              "product_data" : [ {
                "product_name" : "slaed_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5_lite",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27426",
          "name" : "27426",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0308",
          "name" : "ADV-2008-0308",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39897",
          "name" : "slaedcms-index-file-include(39897)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4975",
          "name" : "4975",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in function/sources.php in SLAED CMS 2.5 Lite allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlang parameter to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:slaed:slaed_cms:2.5_lite:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T16:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0459",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "liquidsilvercms",
            "product" : {
              "product_data" : [ {
                "product_name" : "liquidsilvercms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.35",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28619",
          "name" : "28619",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27425",
          "name" : "27425",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0309",
          "name" : "ADV-2008-0309",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39895",
          "name" : "liquidsilvercms-index-file-include(39895)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4976",
          "name" : "4976",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the update parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liquidsilvercms:liquidsilvercms:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liquidsilvercms:liquidsilvercms:0.35:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T16:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0460",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mediawiki",
            "product" : {
              "product_data" : [ {
                "product_name" : "mediawiki",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.0rc1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mediawiki_botquery_ext",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-January/000068.html",
          "name" : "[MediaWiki-announce] 20080124 MediaWiki 1.11.1, 1.10.3, 1.9.5 released",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28629",
          "name" : "28629",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29266",
          "name" : "29266",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28137",
          "name" : "28137",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0280",
          "name" : "ADV-2008-0280",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39901",
          "name" : "mediawiki-api-xss(39901)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00147.html",
          "name" : "FEDORA-2008-2245",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00189.html",
          "name" : "FEDORA-2008-2288",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11 through 1.11.0rc1, 1.10 through 1.10.2, 1.9 through 1.9.4, and 1.8; and (2) the BotQuery extension for MediaWiki 1.7 and earlier; when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.8.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.8.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.9.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.11.0rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki_botquery_ext:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:*:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki_botquery_ext:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-25T16:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0461",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "francisco_burzi",
            "product" : {
              "product_data" : [ {
                "product_name" : "php-nuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0_final",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28624",
          "name" : "28624",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27408",
          "name" : "27408",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0264",
          "name" : "ADV-2008-0264",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39850",
          "name" : "phpnuke-index-search-sql-injection(39850)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4965",
          "name" : "4965",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Search module in PHP-Nuke 8.0 FINAL and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the sid parameter in a comments action to modules.php.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.0_final"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T16:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0462",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "archive_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5_1.7",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "drupal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/213478",
          "name" : "http://drupal.org/node/213478",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28632",
          "name" : "28632",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27436",
          "name" : "27436",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0278",
          "name" : "ADV-2008-0278",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39898",
          "name" : "drupal-archive-unspecified-xss(39898)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Archive 5.x before 5.x-1.8 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:archive_module:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5_1.7"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-25T16:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0463",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "workflow",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7.x-1.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "5.x-1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/213473",
          "name" : "http://drupal.org/node/213473",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28633",
          "name" : "28633",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27444",
          "name" : "27444",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0279",
          "name" : "ADV-2008-0279",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39896",
          "name" : "workflow-messages-xss(39896)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Workflow 4.7.x before 4.7.x-1.2 and 5.x before 5.x-1.2 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving node properties."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:workflow:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.7.x-1.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:workflow:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.x-1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-25T16:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0464",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "absofort",
            "product" : {
              "product_data" : [ {
                "product_name" : "aconon_mail_enterprise_sql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://burnachurch.com/67/directory-traversal-luecke-in-aconon-mail/",
          "name" : "http://burnachurch.com/67/directory-traversal-luecke-in-aconon-mail/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059856.html",
          "name" : "20080124 Directory Traversal Vulnerability in Aconon Mail",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28617",
          "name" : "28617",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27427",
          "name" : "27427",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0310",
          "name" : "ADV-2008-0310",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4977",
          "name" : "4977",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterprise SQL 11.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:absofort:aconon_mail_enterprise_sql:11.5.1:2004:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:absofort:aconon_mail_enterprise_sql:11.7.0:2007:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T16:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0465",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "seagullproject.org",
            "product" : {
              "product_data" : [ {
                "product_name" : "seagull",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://seagullproject.org/publisher/articleview/action/view/frmArticleID/98/",
          "name" : "http://seagullproject.org/publisher/articleview/action/view/frmArticleID/98/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28646",
          "name" : "28646",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2008-January/001891.html",
          "name" : "20080129 Seagull 0.6.3 Remote File Disclosure Vulnerability fixed",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27437",
          "name" : "27437",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0311",
          "name" : "ADV-2008-0311",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39902",
          "name" : "seagullstable-optimizer-directory-traversal(39902)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4980",
          "name" : "4980",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in optimizer.php in Seagull 0.6.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the files parameter."
        }, {
          "lang" : "en",
          "value" : "The vendor has released a patch for 0.6.3.  A patch can be found at the following location: \r\n\r\nhttp://seagullproject.org/download/\r\n\r\n"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:seagullproject.org:seagull:0.6.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-25T16:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0466",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webwiz",
            "product" : {
              "product_data" : [ {
                "product_name" : "web_wiz_forums",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.07",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "web_wiz_newspad",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.02",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "web_wiz_rich_text_editor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3584",
          "name" : "3584",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019267",
          "name" : "1019267",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.bugreport.ir/?/29",
          "name" : "http://www.bugreport.ir/?/29",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.bugreport.ir/?/31",
          "name" : "http://www.bugreport.ir/?/31",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486866/100/0/threaded",
          "name" : "20080123 Web Wiz Forums Directory traversal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486868/100/0/threaded",
          "name" : "20080123 Web Wiz Rich Text Editor Directory traversal + HTM/HTML filecreation on the server",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27419",
          "name" : "27419",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.webwizguide.com/webwizrichtexteditor/kb/release_notes.asp",
          "name" : "http://www.webwizguide.com/webwizrichtexteditor/kb/release_notes.asp",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4970",
          "name" : "4970",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4971",
          "name" : "4971",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files.  NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a separate directory traversal vulnerability."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webwiz:web_wiz_forums:9.07:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webwiz:web_wiz_newspad:1.02:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webwiz:web_wiz_rich_text_editor:4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T00:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0467",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "firebirdsql",
            "product" : {
              "product_data" : [ {
                "product_name" : "firebird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.3",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28596",
          "name" : "28596",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29203",
          "name" : "29203",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29501",
          "name" : "29501",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-02.xml",
          "name" : "GLSA-200803-02",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=9028&release_id=570800",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=9028&release_id=570800",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=570816&group_id=9028",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=570816&group_id=9028",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://tracker.firebirdsql.org/browse/CORE-1603",
          "name" : "http://tracker.firebirdsql.org/browse/CORE-1603",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1529",
          "name" : "DSA-1529",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27467",
          "name" : "27467",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019277",
          "name" : "1019277",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0300",
          "name" : "ADV-2008-0300",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39981",
          "name" : "firebird-username-bo(39981)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote attackers to execute arbitrary code via a long username."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:firebirdsql:firebird:*:rc1:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T02:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0468",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "flinx",
            "product" : {
              "product_data" : [ {
                "product_name" : "flinx",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27448",
          "name" : "27448",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0313",
          "name" : "ADV-2008-0313",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39930",
          "name" : "flinx-category-sql-injection(39930)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4985",
          "name" : "4985",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in category.php in Flinx 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:flinx:flinx:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0469",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tiger_php_news_system",
            "product" : {
              "product_data" : [ {
                "product_name" : "tiger_php_news_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0b",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28641",
          "name" : "28641",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3587",
          "name" : "3587",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486961/100/0/threaded",
          "name" : "20080124 Tiger PHP News System SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27445",
          "name" : "27445",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0312",
          "name" : "ADV-2008-0312",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39908",
          "name" : "tigerphpnewssystem-catid-sql-injection(39908)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4984",
          "name" : "4984",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in Tiger Php News System (TPNS) 1.0b and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newscat action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tiger_php_news_system:tiger_php_news_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0b"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0470",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "comodo",
            "product" : {
              "product_data" : [ {
                "product_name" : "comodo_antivirus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "activex",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27424",
          "name" : "27424",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39904",
          "name" : "comodo-antivirus-command-execution(39904)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4974",
          "name" : "4974",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:comodo:comodo_antivirus:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:activex:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-29T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0471",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpbb",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpbb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.22",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463589",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463589",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28630",
          "name" : "28630",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28871",
          "name" : "28871",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3585",
          "name" : "3585",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1488",
          "name" : "DSA-1488",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487004/100/0/threaded",
          "name" : "20080123 phpBB 2.0.22 Remote PM Delete XSRF Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB 2.0.22 allows remote attackers to delete private messages (PM) as arbitrary users via a deleteall action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb:phpbb:2.0.22:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-29T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0472",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "woltlab",
            "product" : {
              "product_data" : [ {
                "product_name" : "burning_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.6_pl2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28634",
          "name" : "28634",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3586",
          "name" : "3586",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486884/100/0/threaded",
          "name" : "20080123 Woltlab Burning Board 2.3.6 PL2 Remote Delete Thread XSRF Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39878",
          "name" : "wbb-modcp-csrf(39878)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in modcp.php in Woltlab Burning Board (wBB) 2.3.6 PL2 allows remote attackers to delete threads as moderators or administrators via a thread_del action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board:2.3.6_pl2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-29T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0473",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "web_wiz",
            "product" : {
              "product_data" : [ {
                "product_name" : "rich_text_editor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3584",
          "name" : "3584",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.bugreport.ir/?/31",
          "name" : "http://www.bugreport.ir/?/31",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486868/100/0/threaded",
          "name" : "20080123 Web Wiz Rich Text Editor Directory traversal + HTM/HTML filecreation on the server",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27419",
          "name" : "27419",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27420",
          "name" : "27420",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019267",
          "name" : "1019267",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4971",
          "name" : "4971",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:web_wiz:rich_text_editor:4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0474",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "manageengine",
            "product" : {
              "product_data" : [ {
                "product_name" : "applications_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1_build_8100",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28332",
          "name" : "28332",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27443",
          "name" : "27443",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39914",
          "name" : "manageengine-multiple-xss(39914)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) showlink parameter to jsp/DiscoveryProfiles.jsp; the (2) attributeIDs, (3) attributeToSelect, (4) redirectto, and (5) resourceid parameters to (a) jsp/ThresholdActionConfiguration.jsp; the (6) page and (7) redirect parameters to (b) jsp/UpdateGlobalSettings.jsp; and the (8) haid and (9) returnpath parameters to (c) showTile.do.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:manageengine:applications_manager:8.1_build_8100:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-29T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0475",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "manageengine",
            "product" : {
              "product_data" : [ {
                "product_name" : "applications_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1_build_8100",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28332",
          "name" : "28332",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27443",
          "name" : "27443",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39917",
          "name" : "manageengine-home-information-disclosure(39917)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demonstrated by the \"/-\" URI.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:manageengine:applications_manager:8.1_build_8100:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0476",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "manageengine",
            "product" : {
              "product_data" : [ {
                "product_name" : "applications_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1_build_8100",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28332",
          "name" : "28332",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27443",
          "name" : "27443",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39915",
          "name" : "manageengine-checks-security-bypass(39915)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote attackers to obtain sensitive information and change settings via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:manageengine:applications_manager:8.1_build_8100:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0477",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "move_networks_inc",
            "product" : {
              "product_data" : [ {
                "product_name" : "move_media_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28647",
          "name" : "28647",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27438",
          "name" : "27438",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019270",
          "name" : "1019270",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0274",
          "name" : "ADV-2008-0274",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39913",
          "name" : "movenetworks-qmpupgrade-bo(39913)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4979",
          "name" : "4979",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgrade Manager allows remote attackers to execute arbitrary code via a long first argument to the Upgrade method.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:move_networks_inc:move_media_player:1.0.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0478",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "setcms",
            "product" : {
              "product_data" : [ {
                "product_name" : "setcms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.6.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27407",
          "name" : "27407",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39864",
          "name" : "setcms-index-file-include(39864)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4962",
          "name" : "4962",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in index.php in SetCMS 3.6.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set parameter, as demonstrated by sending a certain CLIENT_IP HTTP header in an enter action to index.php, and injecting PHP sequences into files/enter.set, which is then included by index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:setcms:setcms:3.6.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0479",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "web_wiz",
            "product" : {
              "product_data" : [ {
                "product_name" : "newspad",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28416",
          "name" : "28416",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3588",
          "name" : "3588",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.bugreport.ir/?/30",
          "name" : "http://www.bugreport.ir/?/30",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486869/100/0/threaded",
          "name" : "20080123 Web Wiz NewsPad Directory traversal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27419",
          "name" : "27419",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019268",
          "name" : "1019268",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.webwizguide.com/webwiznewspad/kb/release_notes.asp",
          "name" : "http://www.webwizguide.com/webwiznewspad/kb/release_notes.asp",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39863",
          "name" : "newspad-rte-directory-traversal(39863)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4972",
          "name" : "4972",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\\\\ in the sub parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:web_wiz:newspad:1.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0480",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "web_wiz",
            "product" : {
              "product_data" : [ {
                "product_name" : "web_wiz_forums",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.07",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28601",
          "name" : "28601",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3589",
          "name" : "3589",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.bugreport.ir/?/29",
          "name" : "http://www.bugreport.ir/?/29",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486866/100/0/threaded",
          "name" : "20080123 Web Wiz Forums Directory traversal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27419",
          "name" : "27419",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019266",
          "name" : "1019266",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.webwizguide.com/webwizforums/kb/release_notes.asp",
          "name" : "http://www.webwizguide.com/webwizforums/kb/release_notes.asp",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39856",
          "name" : "webwiz-rte-filebrowser-directory-traversal(39856)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4970",
          "name" : "4970",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\\\\ in the sub parameter to (1) RTE_file_browser.asp or (2) file_browser.asp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:web_wiz:web_wiz_forums:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "9.07"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0481",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "web_wiz",
            "product" : {
              "product_data" : [ {
                "product_name" : "rich_text_editor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28639",
          "name" : "28639",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3584",
          "name" : "3584",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019267",
          "name" : "1019267",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.bugreport.ir/?/31",
          "name" : "http://www.bugreport.ir/?/31",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486868/100/0/threaded",
          "name" : "20080123 Web Wiz Rich Text Editor Directory traversal + HTM/HTML filecreation on the server",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27419",
          "name" : "27419",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.webwizguide.com/webwizrichtexteditor/kb/release_notes.asp",
          "name" : "http://www.webwizguide.com/webwizrichtexteditor/kb/release_notes.asp",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39868",
          "name" : "editor-rte-directory-traversal(39868)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4971",
          "name" : "4971",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\\\\ in the sub parameter in a save action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:web_wiz:rich_text_editor:4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-29T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0485",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mplayer",
            "product" : {
              "product_data" : [ {
                "product_name" : "mplayer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.02rc2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060032.html",
          "name" : "20080204 CORE-2008-0122: MPlayer arbitrary pointer dereference",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28779",
          "name" : "28779",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28955",
          "name" : "28955",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28956",
          "name" : "28956",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29307",
          "name" : "29307",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-16.xml",
          "name" : "GLSA-200803-16",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3607",
          "name" : "3607",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.coresecurity.com/?action=item&id=2102",
          "name" : "http://www.coresecurity.com/?action=item&id=2102",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1496",
          "name" : "DSA-1496",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:045",
          "name" : "MDVSA-2008:045",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mplayerhq.hu/design7/news.html",
          "name" : "http://www.mplayerhq.hu/design7/news.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487500/100/0/threaded",
          "name" : "20080204 CORE-2008-0122: MPlayer arbitrary pointer dereference",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27499",
          "name" : "27499",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019299",
          "name" : "1019299",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0406/references",
          "name" : "ADV-2008-0406",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV file with a crafted stsc atom tag."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mplayer:mplayer:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.02rc2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-05T12:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0486",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mplayer",
            "product" : {
              "product_data" : [ {
                "product_name" : "mplayer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.02rc2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "xine",
            "product" : {
              "product_data" : [ {
                "product_name" : "xine-lib",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=209106",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=209106",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://bugs.xine-project.org/show_bug.cgi?id=38",
          "name" : "http://bugs.xine-project.org/show_bug.cgi?id=38",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060033.html",
          "name" : "20080204 CORE-2007-1218: MPlayer 1.0rc2 buffer overflow vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html",
          "name" : "SUSE-SR:2008:006",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28779",
          "name" : "28779",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28801",
          "name" : "28801",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28918",
          "name" : "28918",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28955",
          "name" : "28955",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28956",
          "name" : "28956",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28989",
          "name" : "28989",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29141",
          "name" : "29141",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29307",
          "name" : "29307",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29323",
          "name" : "29323",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29601",
          "name" : "29601",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31393",
          "name" : "31393",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200802-12.xml",
          "name" : "GLSA-200802-12",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-16.xml",
          "name" : "GLSA-200803-16",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3608",
          "name" : "3608",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=9655&release_id=574735",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=9655&release_id=574735",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.coresecurity.com/?action=item&id=2103",
          "name" : "http://www.coresecurity.com/?action=item&id=2103",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1496",
          "name" : "DSA-1496",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1536",
          "name" : "DSA-1536",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:045",
          "name" : "MDVSA-2008:045",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:046",
          "name" : "MDVSA-2008:046",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mplayerhq.hu/design7/news.html",
          "name" : "http://www.mplayerhq.hu/design7/news.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487501/100/0/threaded",
          "name" : "20080204 CORE-2007-1218: MPlayer 1.0rc2 buffer overflow vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27441",
          "name" : "27441",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-635-1",
          "name" : "USN-635-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0406/references",
          "name" : "ADV-2008-0406",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0421",
          "name" : "ADV-2008-0421",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=431541",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=431541",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00395.html",
          "name" : "FEDORA-2008-1543",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00442.html",
          "name" : "FEDORA-2008-1581",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mplayer:mplayer:1.02rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xine:xine-lib:1.1.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T12:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0487",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "the_net_guys",
            "product" : {
              "product_data" : [ {
                "product_name" : "aspired2protect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28653",
          "name" : "28653",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3598",
          "name" : "3598",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487137/100/0/threaded",
          "name" : "20080126 ASPired2Protect bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27474",
          "name" : "27474",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39989",
          "name" : "aspired2protect-login-sql-injection(39989)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in login.asp in ASPired2Protect allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:the_net_guys:aspired2protect:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-30T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0488",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vb_marketing",
            "product" : {
              "product_data" : [ {
                "product_name" : "vb_marketing",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3596",
          "name" : "3596",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487174/100/0/threaded",
          "name" : "20080128 VB Marketing \"tseekdir.cgi\" Local File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27475",
          "name" : "27475",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39970",
          "name" : "vbmarketing-tseekdir-file-include(39970)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in tseekdir.cgi in VB Marketing allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the location parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vb_marketing:vb_marketing:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-30T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0489",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clansphere",
            "product" : {
              "product_data" : [ {
                "product_name" : "clansphere",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007.4.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3597",
          "name" : "3597",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487132/100/0/threaded",
          "name" : "20080127 ClanSphere 2007.4.4 Remote File Disclosure Vulnerability.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27471",
          "name" : "27471",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39977",
          "name" : "clansphere-install-directory-traversal(39977)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in install.php in Clansphere 2007.4.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clansphere:clansphere:2007.4.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-30T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0490",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wp_cal_plugin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28683",
          "name" : "28683",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27465",
          "name" : "27465",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0348",
          "name" : "ADV-2008-0348",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39966",
          "name" : "wpcal-editevent-sql-injection(39966)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4992",
          "name" : "4992",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wp_cal_plugin:0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-30T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0491",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "fgallery_plugin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27464",
          "name" : "27464",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0349",
          "name" : "ADV-2008-0349",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39964",
          "name" : "fgallery-fimrss-sql-injection(39964)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4993",
          "name" : "4993",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the album parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:fgallery_plugin:2.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-30T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0492",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "persits",
            "product" : {
              "product_data" : [ {
                "product_name" : "xupload",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28660",
          "name" : "28660",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27456",
          "name" : "27456",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0315",
          "name" : "ADV-2008-0315",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39967",
          "name" : "persits-xupload-bo(39967)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4987",
          "name" : "4987",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the Persits.XUpload.2 ActiveX control in XUpload.ocx 3.0.0.4 and earlier in Persits XUpload 3.0 allows remote attackers to execute arbitrary code via a long argument to the AddFile method.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:persits:xupload:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-30T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0493",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "irfanview",
            "product" : {
              "product_data" : [ {
                "product_name" : "irfanview",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28688",
          "name" : "28688",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27479",
          "name" : "27479",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0318",
          "name" : "ADV-2008-0318",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40012",
          "name" : "irfanview-flashpix-bo(40012)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4998",
          "name" : "4998",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:irfanview:irfanview:4.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-30T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0494",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "endian",
            "product" : {
              "product_data" : [ {
                "product_name" : "firewall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://downloads.securityfocus.com/vulnerabilities/exploits/27477.html",
          "name" : "http://downloads.securityfocus.com/vulnerabilities/exploits/27477.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27477",
          "name" : "27477",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in vpnum/userslist.php in Endian Firewall 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the psearch parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:endian:firewall:2.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-30T22:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0495",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "hardware_management_console",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.3.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28667",
          "name" : "28667",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29056",
          "name" : "29056",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27484",
          "name" : "27484",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019280",
          "name" : "1019280",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0323",
          "name" : "ADV-2008-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0638",
          "name" : "ADV-2008-0638",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=isg1MB02236",
          "name" : "MB02236",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4129",
          "name" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4129",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40021",
          "name" : "hmc-pegasus-cim-dos(40021)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www14.software.ibm.com/webapp/set2/sas/f/hmc/power6/install/v7.Readme.html",
          "name" : "https://www14.software.ibm.com/webapp/set2/sas/f/hmc/power6/install/v7.Readme.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.0 allows remote attackers to cause a denial of service via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:hardware_management_console:7.3.2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-30T22:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0496",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ampjuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "ampjuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28661",
          "name" : "28661",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3594",
          "name" : "3594",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487258/100/0/threaded",
          "name" : "20080129 AmpJuke-0.7.0 (index.php) Xss VuLn.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27498",
          "name" : "27498",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0332",
          "name" : "ADV-2008-0332",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40023",
          "name" : "juke-index-xss(40023)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in AmpJuke 0.7.0 allows remote attackers to inject arbitrary web script or HTML via the limit parameter in a search action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ampjuke:ampjuke:0.7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-30T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0497",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nucleus_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "nucleus_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.31",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28680",
          "name" : "28680",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3593",
          "name" : "3593",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=66479&release_id=572117",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=66479&release_id=572117",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.nucleuscms.org/item/3047",
          "name" : "http://www.nucleuscms.org/item/3047",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487252/100/0/threaded",
          "name" : "20080129 Nucleus 3.31 XSS in path",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487255/100/0/threaded",
          "name" : "20080129 [!!FIX Information ] Nucleus 3.31 XSS in path",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27492",
          "name" : "27492",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0369",
          "name" : "ADV-2008-0369",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in action.php in Nucleus CMS 3.31 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, which is not quoted when processing PHP_SELF."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nucleus_cms:nucleus_cms:3.31:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-30T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0498",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bigware",
            "product" : {
              "product_data" : [ {
                "product_name" : "bigware_shop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28691",
          "name" : "28691",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27489",
          "name" : "27489",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0351",
          "name" : "ADV-2008-0351",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40010",
          "name" : "bigwareshop-mainbigware-sql-injection(40010)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5002",
          "name" : "5002",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in main_bigware_53.tpl.php in Bigware Shop 2.0 allows remote attackers to execute arbitrary SQL commands via the pollid parameter in a results action to main_bigware_53.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bigware:bigware_shop:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-30T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0499",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mamboxchange",
            "product" : {
              "product_data" : [ {
                "product_name" : "laithai",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28652",
          "name" : "28652",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=192544&release_id=571300",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=192544&release_id=571300",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27483",
          "name" : "27483",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0316",
          "name" : "ADV-2008-0316",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40013",
          "name" : "mambo-laithai-unspecified-sql-injection(40013)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Mambo LaiThai 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mamboxchange:laithai:4.5.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-30T22:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0500",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mamboxchange",
            "product" : {
              "product_data" : [ {
                "product_name" : "laithai",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28652",
          "name" : "28652",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=192544&release_id=571300",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=192544&release_id=571300",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27483",
          "name" : "27483",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0316",
          "name" : "ADV-2008-0316",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40014",
          "name" : "mambo-laithai-multiple-unspecified(40014)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Mambo LaiThai 4.5.5 have unknown impact and attack vectors related to (1) mod_login and (2) mod_template_chooser."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mamboxchange:laithai:4.5.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-30T22:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0501",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sourceforge",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpmyclub",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27480",
          "name" : "27480",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0350",
          "name" : "ADV-2008-0350",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40007",
          "name" : "phpmyclub-pagecourante-file-include(40007)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5000",
          "name" : "5000",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page_courante parameter to the top-level URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sourceforge:phpmyclub:0.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-30T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0502",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "connectix",
            "product" : {
              "product_data" : [ {
                "product_name" : "connectix_boards",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28704",
          "name" : "28704",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27506",
          "name" : "27506",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0363",
          "name" : "ADV-2008-0363",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40040",
          "name" : "connectixboards-templatepath-file-include(40040)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5012",
          "name" : "5012",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in templates/Official/part_userprofile.php in Connectix Boards 0.8.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the template_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:connectix:connectix_boards:0.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:connectix:connectix_boards:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.8.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0503",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "netwerk",
            "product" : {
              "product_data" : [ {
                "product_name" : "smart_publisher",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28685",
          "name" : "28685",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27488",
          "name" : "27488",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0352",
          "name" : "ADV-2008-0352",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5003",
          "name" : "5003",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Eval injection vulnerability in admin/op/disp.php in Netwerk Smart Publisher 1.0.1 allows remote attackers to execute arbitrary PHP code via the filedata parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwerk:smart_publisher:1.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0504",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "coppermine-gallery",
            "product" : {
              "product_data" : [ {
                "product_name" : "coppermine_photo_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.14",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://coppermine-gallery.net/forum/index.php?topic=50103.0",
          "name" : "http://coppermine-gallery.net/forum/index.php?topic=50103.0",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28682",
          "name" : "28682",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487351/100/200/threaded",
          "name" : "20080131 [waraxe-2008-SA#066] - Multiple Vulnerabilities in Coppermine 1.4.14",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27509",
          "name" : "27509",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019285",
          "name" : "1019285",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0367",
          "name" : "ADV-2008-0367",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.waraxe.us/advisory-66.html",
          "name" : "http://www.waraxe.us/advisory-66.html",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cid_array parameter to reviewcom.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.1:beta_2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.2.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.2.1:b:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.2.1:b-nuke:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.4.0:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.4.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.4.1:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.4.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.4.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4.14"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2018-10-16T16:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0505",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "coppermine",
            "product" : {
              "product_data" : [ {
                "product_name" : "coppermine_photo_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.14",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://coppermine-gallery.net/forum/index.php?topic=50103.0",
          "name" : "http://coppermine-gallery.net/forum/index.php?topic=50103.0",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28682",
          "name" : "28682",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487351/100/200/threaded",
          "name" : "20080131 [waraxe-2008-SA#066] - Multiple Vulnerabilities in Coppermine 1.4.14",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27511",
          "name" : "27511",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019285",
          "name" : "1019285",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0367",
          "name" : "ADV-2008-0367",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.waraxe.us/advisory-66.html",
          "name" : "http://www.waraxe.us/advisory-66.html",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.4.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.4.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4.14"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0506",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "coppermine",
            "product" : {
              "product_data" : [ {
                "product_name" : "coppermine_photo_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.14",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://coppermine-gallery.net/forum/index.php?topic=50103.0",
          "name" : "http://coppermine-gallery.net/forum/index.php?topic=50103.0",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28682",
          "name" : "28682",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487310/100/200/threaded",
          "name" : "20080130 [waraxe-2008-SA#065] - Remote Shell Command Execution in Coppermine 1.4.14",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27512",
          "name" : "27512",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019286",
          "name" : "1019286",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0367",
          "name" : "ADV-2008-0367",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.waraxe.us/advisory-65.html",
          "name" : "http://www.waraxe.us/advisory-65.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5019",
          "name" : "5019",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4.14"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0507",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "adserve",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28708",
          "name" : "28708",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27504",
          "name" : "27504",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0364",
          "name" : "ADV-2008-0364",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40045",
          "name" : "adserve-adclick-sql-injection(40045)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5013",
          "name" : "5013",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:adserve:0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0508",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "permalinks_migration_plugin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://g30rg3x.com/wp-files/dpm_11gx.zip",
          "name" : "http://g30rg3x.com/wp-files/dpm_11gx.zip",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://g30rg3x.com/xsrf-bajo-deans-permalinks-migration-10",
          "name" : "http://g30rg3x.com/xsrf-bajo-deans-permalinks-migration-10",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://packetstorm.linuxsecurity.com/0801-advisories/deans-xsrf.txt",
          "name" : "http://packetstorm.linuxsecurity.com/0801-advisories/deans-xsrf.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28593",
          "name" : "28593",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3595",
          "name" : "3595",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486840/100/0/threaded",
          "name" : "20080122 XSRF under Dean&acirc;??s Permalinks Migration 1.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0281",
          "name" : "ADV-2008-0281",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39845",
          "name" : "permalinks-deanpmconfig-csrf(39845)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows remote attackers to modify the oldstructure (aka dean_pm_config[oldstructure]) configuration setting as administrators via the old_struct parameter in a deans_permalinks_migration.php action to wp-admin/options-general.php, as demonstrated by placing an XSS sequence in this setting."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:permalinks_migration_plugin:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0509",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28600",
          "name" : "28600",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27510",
          "name" : "27510",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0324",
          "name" : "ADV-2008-0324",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=isg1IZ13739",
          "name" : "IZ13739",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5796",
          "name" : "oval:org.mitre.oval:def:5796",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in IBM AIX 4.3 allow remote attackers to cause a denial of service (crash) or possibly gain privileges via a long argument to (1) piox25, related to piox25.c; or (2) piox25remote, related to piox25remote.sh."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:4.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:S/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 2.7,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0510",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_newsletter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_newsletter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mambo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27502",
          "name" : "27502",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0354",
          "name" : "ADV-2008-0354",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40036",
          "name" : "newsletter-index-sql-injection(40036)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5007",
          "name" : "5007",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Newsletter (com_newsletter) component for Mambo 4.5 and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_newsletter:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_newsletter:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0511",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_mamml",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_mamml",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27503",
          "name" : "27503",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0356",
          "name" : "ADV-2008-0356",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40037",
          "name" : "mamml-index-sql-injection(40037)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5009",
          "name" : "5009",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the MaMML (com_mamml) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_mamml:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_mamml:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0512",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_fq",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27501",
          "name" : "27501",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0355",
          "name" : "ADV-2008-0355",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40035",
          "name" : "fq-index-sql-injection(40035)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5008",
          "name" : "5008",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the fq (com_fq) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_fq:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0513",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpcms",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpcms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28709",
          "name" : "28709",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487251/100/0/threaded",
          "name" : "20080129 Remote File Disclosure in phpCMS 1.2.2",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487254/100/0/threaded",
          "name" : "20080129 Re: Remote File Disclosure in phpCMS 1.2.2",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27495",
          "name" : "27495",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0353",
          "name" : "ADV-2008-0353",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40017",
          "name" : "phpcms-parser-directory-traversal(40017)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5006",
          "name" : "5006",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to parser/parser.php, as demonstrated by a filename ending with %00.gif, a different vector than CVE-2005-1840."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpcms:phpcms:1.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0514",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "glossary",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "glossary",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27505",
          "name" : "27505",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0357",
          "name" : "ADV-2008-0357",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40038",
          "name" : "glossary-index-sql-injection(40038)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5010",
          "name" : "5010",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Glossary (com_glossary) 2.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:glossary:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:glossary:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0515",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "musepoes_component",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "musepoes_component",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27507",
          "name" : "27507",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0358",
          "name" : "ADV-2008-0358",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5011",
          "name" : "5011",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the musepoes (com_musepoes) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:musepoes_component:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:musepoes_component:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0516",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sqlite_manager",
            "product" : {
              "product_data" : [ {
                "product_name" : "sqlite_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28642",
          "name" : "28642",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27515",
          "name" : "27515",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40065",
          "name" : "sqlitemanager-confirm-file-include(40065)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in spaw/dialogs/confirm.php in SQLiteManager 1.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sqlite_manager:sqlite_manager:1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0517",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "darko_selesi",
            "product" : {
              "product_data" : [ {
                "product_name" : "estateagent",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "joomla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "mambo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.1_1.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.1_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.1_beta2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.3h",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5_1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5_1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5_1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5_1.0.3_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5_1.0.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27520",
          "name" : "27520",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0362",
          "name" : "ADV-2008-0362",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40060",
          "name" : "estateagent-index-sql-injection(40060)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5016",
          "name" : "5016",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL commands via the objid parameter in a contact showObject action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:darko_selesi:estateagent:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5.1_1.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5.1_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5.1_beta2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5.1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5.3h:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5_1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5_1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5_1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5_1.0.3_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5_1.0.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0518",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_recipes",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.00",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_recipes",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.00",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27519",
          "name" : "27519",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0360",
          "name" : "ADV-2008-0360",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40064",
          "name" : "recipes-index-sql-injection(40064)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5014",
          "name" : "5014",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Recipes (com_recipes) 1.00 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_recipes:1.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_recipes:1.00:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0519",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_jokes",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_jokes",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27522",
          "name" : "27522",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0361",
          "name" : "ADV-2008-0361",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40067",
          "name" : "jokes-index-sql-injection(40067)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5015",
          "name" : "5015",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Atapin Jokes (com_jokes) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a CatView action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_jokes:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_jokes:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0520",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wassup_plugin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28702",
          "name" : "28702",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27525",
          "name" : "27525",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0365",
          "name" : "ADV-2008-0365",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.wpwp.org/archives/warning-security-bug-in-version/",
          "name" : "http://www.wpwp.org/archives/warning-security-bug-in-version/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5017",
          "name" : "5017",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) from_date or (2) to_date parameter to spy.php."
        }, {
          "lang" : "en",
          "value" : "Additional research found the following links:\r\n\r\nhttp://secunia.com/advisories/28702/\r\n\r\nhttp://www.securityfocus.com/bid/27525"
        }, {
          "lang" : "en",
          "value" : "Additional research found the following link:\r\nhttp://downloads.wordpress.org/plugin/wassup.1.4.3a.zip"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wassup_plugin:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wassup_plugin:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0521",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bubbling_library",
            "product" : {
              "product_data" : [ {
                "product_name" : "bubbling_library",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.32",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27482",
          "name" : "27482",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40008",
          "name" : "bubbling-dispatcher-directory-traversal(40008)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5001",
          "name" : "5001",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to read arbitrary files via a .. (dot dot) in the uri parameter to dispatcher.php in (1) examples/dispatcher/framework/, (2) examples/dispatcher/, (3) examples/wizard/, and (4) PHP/, different vectors than CVE-2008-0545."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bubbling_library:bubbling_library:1.32:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0522",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hal_networks",
            "product" : {
              "product_data" : [ {
                "product_name" : "perl__cgi_cart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "php_cart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "shop_hal_v1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jvn.jp/jp/JVN%2301162446/index.html",
          "name" : "JVN#01162446",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28692",
          "name" : "28692",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.hal9800.com/home/bug/20080123.html",
          "name" : "http://www.hal9800.com/home/bug/20080123.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.hal9800.com/home/bug/20080127.html",
          "name" : "http://www.hal9800.com/home/bug/20080127.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.hal9800.com/home/bug/20080128.html",
          "name" : "http://www.hal9800.com/home/bug/20080128.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.hal9800.com/home/bug/20080129.html",
          "name" : "http://www.hal9800.com/home/bug/20080129.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27513",
          "name" : "27513",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0368",
          "name" : "ADV-2008-0368",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in multiple Hal Networks shopping-cart products allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hal_networks:perl__cgi_cart:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hal_networks:php_cart:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hal_networks:shop_hal_v1:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2011-03-08T03:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0523",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "softcart",
            "product" : {
              "product_data" : [ {
                "product_name" : "softcart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28675",
          "name" : "28675",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27524",
          "name" : "27524",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40061",
          "name" : "softcart-softcart-xss(40061)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in SoftCart.exe in SoftCart 5.1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) License_Plate, (2) License_State, (3) Ticket_Date, and (4) Ticket_Number parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:softcart:softcart:5.1.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0524",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "yamaha",
            "product" : {
              "product_data" : [ {
                "product_name" : "rt107e",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rt52pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rt56v",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rt57i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rt58i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rt60w",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rt80i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rta50i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rta52i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rta54i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rta55i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rtv700",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rtw65b",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rtw65i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rtx1000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rtx1100",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rtx1500",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "srt100",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jvn.jp/jp/JVN%2388575577/index.html",
          "name" : "JVN#88575577",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28690",
          "name" : "28690",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVN88575577.html",
          "name" : "http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVN88575577.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27491",
          "name" : "27491",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40015",
          "name" : "yamaha-routers-http-csrf(40015)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in the management interface in multiple Yamaha RT series routers allows remote attackers to change password settings and probably other configuration settings as administrators via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rt107e:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rt52pro:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rt56v:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rt57i:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rt58i:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rt60w:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rt80i:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rta50i:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rta52i:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rta54i:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rta55i:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rtv700:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rtw65b:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rtw65i:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rtx1000:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rtx1100:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:rtx1500:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:yamaha:srt100:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0525",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lumension_security",
            "product" : {
              "product_data" : [ {
                "product_name" : "patchlink_update",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "novell",
            "product" : {
              "product_data" : [ {
                "product_name" : "zenworks_patch_management_update_agent",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-59"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28657",
          "name" : "28657",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28665",
          "name" : "28665",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3599",
          "name" : "3599",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://support.lumension.com/scripts/rightnow.cfg/php.exe/enduser/std_adp.php?p_faqid=527",
          "name" : "http://support.lumension.com/scripts/rightnow.cfg/php.exe/enduser/std_adp.php?p_faqid=527",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.lumension.com/scripts/rightnow.cfg/php.exe/enduser/std_adp.php?p_faqid=528",
          "name" : "http://support.lumension.com/scripts/rightnow.cfg/php.exe/enduser/std_adp.php?p_faqid=528",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.lumension.com/scripts/rightnow.cfg/php.exe/enduser/std_adp.php?p_faqid=530",
          "name" : "http://support.lumension.com/scripts/rightnow.cfg/php.exe/enduser/std_adp.php?p_faqid=530",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487103/100/0/threaded",
          "name" : "20080125 Two vulnerabilities for PatchLink Update Client for Unix.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27458",
          "name" : "27458",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019272",
          "name" : "1019272",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0426",
          "name" : "ADV-2008-0426",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39956",
          "name" : "patchlinkupdate-logtrimmer-symlink(39956)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39958",
          "name" : "patchlinkupdate-reboottask-symlink(39958)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://secure-support.novell.com/KanisaPlatform/Publishing/18/3908994_f.SAL_Public.html",
          "name" : "https://secure-support.novell.com/KanisaPlatform/Publishing/18/3908994_f.SAL_Public.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PatchLink Update client for Unix, as used by Novell ZENworks Patch Management Update Agent for Linux/Unix/Mac (LUM) 6.2094 through 6.4102 and other products, allows local users to (1) truncate arbitrary files via a symlink attack on the /tmp/patchlink.tmp file used by the logtrimmer script, and (2) execute arbitrary code via a symlink attack on the /tmp/plshutdown file used by the rebootTask script."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:unix:unix:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:lumension_security:patchlink_update:6.2:*:linux:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:lumension_security:patchlink_update:6.2:*:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:lumension_security:patchlink_update:6.2:*:unix:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:lumension_security:patchlink_update:6.3:*:linux:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:lumension_security:patchlink_update:6.3:*:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:lumension_security:patchlink_update:6.3:*:unix:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:lumension_security:patchlink_update:6.4:*:linux:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:lumension_security:patchlink_update:6.4:*:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:lumension_security:patchlink_update:6.4:*:unix:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:novell:zenworks_patch_management_update_agent:6.2:*:linux:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:novell:zenworks_patch_management_update_agent:6.2:*:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:novell:zenworks_patch_management_update_agent:6.2:*:unix:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:novell:zenworks_patch_management_update_agent:6.3:*:linux:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:novell:zenworks_patch_management_update_agent:6.3:*:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:novell:zenworks_patch_management_update_agent:6.3:*:unix:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:novell:zenworks_patch_management_update_agent:6.4:*:linux:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:novell:zenworks_patch_management_update_agent:6.4:*:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:novell:zenworks_patch_management_update_agent:6.4:*:unix:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-31T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0526",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "session_initiation_protocol_(sip)_firmware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "skinny_client_control_protocol_(sccp)_firmware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28935",
          "name" : "28935",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml",
          "name" : "20080213 Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities",
          "refsource" : "CISCO",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27774",
          "name" : "27774",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019407",
          "name" : "1019407",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0543",
          "name" : "ADV-2008-0543",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40487",
          "name" : "cisco-unifiedipphone-icmp-dos(40487)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a long ICMP echo request (ping) packet."
        }, {
          "lang" : "en",
          "value" : "In order to download the patch, login is required"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7906g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7911g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7935:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7936:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7941g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7961g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7970g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7971g:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:skinny_client_control_protocol_\\(sccp\\)_firmware:*:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960g:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:session_initiation_protocol_\\(sip\\)_firmware:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T02:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0527",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "session_initiation_protocol_(sip)_firmware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "skinny_client_control_protocol_(sccp)_firmware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28935",
          "name" : "28935",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml",
          "name" : "20080213 Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities",
          "refsource" : "CISCO",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27774",
          "name" : "27774",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019408",
          "name" : "1019408",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0543",
          "name" : "ADV-2008-0543",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40489",
          "name" : "cisco-unifiedipphone-httpserver-dos(40489)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The HTTP server in Cisco Unified IP Phone 7935 and 7936 running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a crafted HTTP request."
        }, {
          "lang" : "en",
          "value" : "Patch download requires login"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7906g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7911g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7935:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7936:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7941g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7961g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7970g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7971g:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:skinny_client_control_protocol_\\(sccp\\)_firmware:*:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960g:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:session_initiation_protocol_\\(sip\\)_firmware:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T02:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0528",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "session_initiation_protocol_(sip)_firmware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "skinny_client_control_protocol_(sccp)_firmware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28935",
          "name" : "28935",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml",
          "name" : "20080213 Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities",
          "refsource" : "CISCO",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27774",
          "name" : "27774",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019409",
          "name" : "1019409",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0543",
          "name" : "ADV-2008-0543",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40492",
          "name" : "cisco-unifiedipphone-sipmime-bo(40492)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote attackers to execute arbitrary code via a SIP message with crafted MIME data."
        }, {
          "lang" : "en",
          "value" : "Patch requires login"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7906g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7911g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7935:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7936:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7941g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7961g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7970g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7971g:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:skinny_client_control_protocol_\\(sccp\\)_firmware:*:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960g:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:session_initiation_protocol_\\(sip\\)_firmware:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T02:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0529",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "session_initiation_protocol_(sip)_firmware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "skinny_client_control_protocol_(sccp)_firmware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28935",
          "name" : "28935",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml",
          "name" : "20080213 Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities",
          "refsource" : "CISCO",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27774",
          "name" : "27774",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019410",
          "name" : "1019410",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0543",
          "name" : "ADV-2008-0543",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40493",
          "name" : "cisco-unifiedipphone-telnet-bo(40493)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code via a crafted command."
        }, {
          "lang" : "en",
          "value" : "Patch requires login"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7906g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7911g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7935:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7936:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7941g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7961g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7970g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7971g:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:skinny_client_control_protocol_\\(sccp\\)_firmware:*:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960g:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:session_initiation_protocol_\\(sip\\)_firmware:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T02:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0530",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "session_initiation_protocol_(sip)_firmware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "skinny_client_control_protocol_(sccp)_firmware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28935",
          "name" : "28935",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml",
          "name" : "20080213 Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities",
          "refsource" : "CISCO",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27774",
          "name" : "27774",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019406",
          "name" : "1019406",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0543",
          "name" : "ADV-2008-0543",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40485",
          "name" : "cisco-unifiedipphone-dns-bo(40485)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP and SIP firmware might allow remote attackers to execute arbitrary code via a crafted DNS response."
        }, {
          "lang" : "en",
          "value" : "Patch requires login"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7906g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7911g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7935:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7936:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7941g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7961g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7970g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7971g:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:skinny_client_control_protocol_\\(sccp\\)_firmware:*:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960g:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:session_initiation_protocol_\\(sip\\)_firmware:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T02:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0531",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "session_initiation_protocol_(sip)_firmware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "skinny_client_control_protocol_(sccp)_firmware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28935",
          "name" : "28935",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml",
          "name" : "20080213 Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities",
          "refsource" : "CISCO",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27774",
          "name" : "27774",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019411",
          "name" : "1019411",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0543",
          "name" : "ADV-2008-0543",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40498",
          "name" : "cisco-unifiedipphone-sipproxy-bo(40498)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote SIP servers to execute arbitrary code via a crafted challenge/response message."
        }, {
          "lang" : "en",
          "value" : "Patch requires login"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7906g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7911g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7935:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7936:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7941g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7961g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7970g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7971g:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:skinny_client_control_protocol_\\(sccp\\)_firmware:*:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7940g:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:unified_ip_phone:7960g:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:session_initiation_protocol_\\(sip\\)_firmware:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T02:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0532",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "acs_for_windows",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "acs_solution_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "user_changeable_password",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29351",
          "name" : "29351",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3743",
          "name" : "3743",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019608",
          "name" : "1019608",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a008095f0c4.shtml",
          "name" : "20080312 Cisco Secure Access Control Server for Windows User-Changeable Password Vulnerabilities",
          "refsource" : "CISCO",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.recurity-labs.com/content/pub/RecurityLabs_Cisco_ACS_UCP_advisory.txt",
          "name" : "http://www.recurity-labs.com/content/pub/RecurityLabs_Cisco_ACS_UCP_advisory.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489463/100/0/threaded",
          "name" : "20080312 Cisco ACS UCP Remote Pre-Authentication Buffer Overflows",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28222",
          "name" : "28222",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0868",
          "name" : "ADV-2008-0868",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41154",
          "name" : "cisco-acs-ucp-csusercgi-bo(41154)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to execute arbitrary code via a long argument located immediately after the Logout argument, and possibly unspecified other vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:acs_for_windows:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:acs_solution_engine:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:user_changeable_password:4.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-14T20:44Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0533",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "acs_for_windows",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "acs_solution_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "user_changeable_password",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29351",
          "name" : "29351",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3743",
          "name" : "3743",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019607",
          "name" : "1019607",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a008095f0c4.shtml",
          "name" : "20080312 Cisco Secure Access Control Server for Windows User-Changeable Password Vulnerabilities",
          "refsource" : "CISCO",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.recurity-labs.com/content/pub/RecurityLabs_Cisco_ACS_UCP_advisory.txt",
          "name" : "http://www.recurity-labs.com/content/pub/RecurityLabs_Cisco_ACS_UCP_advisory.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489463/100/0/threaded",
          "name" : "20080312 Cisco ACS UCP Remote Pre-Authentication Buffer Overflows",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28222",
          "name" : "28222",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0868",
          "name" : "ADV-2008-0868",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41156",
          "name" : "cisco-acs-ucp-csusercgi-xss(41156)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary web script or HTML via an argument located immediately after the Help argument, and possibly unspecified other vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:acs_for_windows:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:acs_solution_engine:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:user_changeable_password:4.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-14T20:44Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0534",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "service_control_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "icon-labs",
            "product" : {
              "product_data" : [ {
                "product_name" : "iconfidant_ssh",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/30316",
          "name" : "30316",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30590",
          "name" : "30590",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1020074",
          "name" : "1020074",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a008099bf65.shtml",
          "name" : "20080521 Cisco Service Control Engine Denial of Service Vulnerabilities",
          "refsource" : "CISCO",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.icon-labs.com/news/read.asp?newsID=77",
          "name" : "http://www.icon-labs.com/news/read.asp?newsID=77",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/626979",
          "name" : "VU#626979",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29316",
          "name" : "29316",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29609",
          "name" : "29609",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1604/references",
          "name" : "ADV-2008-1604",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1774/references",
          "name" : "ADV-2008-1774",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42565",
          "name" : "cisco-sce-sshlogin-dos(42565)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The SSH server in (1) Cisco Service Control Engine (SCE) before 3.1.6, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (device restart or daemon outage) via a high rate of login attempts, aka Bug ID CSCsi68582."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:service_control_engine:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.1.6"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:icon-labs:iconfidant_ssh:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.3.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-05-22T13:09Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0535",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "service_control_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "icon-labs",
            "product" : {
              "product_data" : [ {
                "product_name" : "iconfidant_ssh",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-255"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/30316",
          "name" : "30316",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30590",
          "name" : "30590",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1020074",
          "name" : "1020074",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a008099bf65.shtml",
          "name" : "20080521 Cisco Service Control Engine Denial of Service Vulnerabilities",
          "refsource" : "CISCO",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.icon-labs.com/news/read.asp?newsID=77",
          "name" : "http://www.icon-labs.com/news/read.asp?newsID=77",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/626979",
          "name" : "VU#626979",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29316",
          "name" : "29316",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29609",
          "name" : "29609",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1604/references",
          "name" : "ADV-2008-1604",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1774/references",
          "name" : "ADV-2008-1774",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42567",
          "name" : "cisco-sce-ssh-credentials-dos(42567)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) before 3.1.6, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (device instability) via \"SSH credentials that attempt to change the authentication method,\" aka Bug ID CSCsm14239."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:service_control_engine:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.1.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:icon-labs:iconfidant_ssh:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.3.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-05-22T13:09Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0536",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "service_control_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "icon-labs",
            "product" : {
              "product_data" : [ {
                "product_name" : "iconfidant_ssh",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/30316",
          "name" : "30316",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30590",
          "name" : "30590",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1020074",
          "name" : "1020074",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a008099bf65.shtml",
          "name" : "20080521 Cisco Service Control Engine Denial of Service Vulnerabilities",
          "refsource" : "CISCO",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.icon-labs.com/news/read.asp?newsID=77",
          "name" : "http://www.icon-labs.com/news/read.asp?newsID=77",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/626979",
          "name" : "VU#626979",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29316",
          "name" : "29316",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29609",
          "name" : "29609",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1604/references",
          "name" : "ADV-2008-1604",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1774/references",
          "name" : "ADV-2008-1774",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42566",
          "name" : "cisco-sce-managementagent-dos(42566)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) 3.0.x before 3.0.7 and 3.1.x before 3.1.0, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (management interface outage) via SSH traffic that occurs during management operations and triggers \"illegal I/O operations,\" aka Bug ID CSCsh49563."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:service_control_engine:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:service_control_engine:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.1.6"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:icon-labs:iconfidant_ssh:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.3.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-05-22T13:09Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0537",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "route_switch_processor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "rsp720",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "supervisor_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "sup32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sup720",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29559",
          "name" : "29559",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20080326-queue.shtml",
          "name" : "20080326 Vulnerability in Cisco IOS with OSPF, MPLS VPN, and Supervisor 32, Supervisor 720, or Route Switch Processor 720",
          "refsource" : "CISCO",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28463",
          "name" : "28463",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019716",
          "name" : "1019716",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-087B.html",
          "name" : "TA08-087B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1005/references",
          "name" : "ADV-2008-1005",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41466",
          "name" : "cisco-catalyst-sup-rsp-dos(41466)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Supervisor Engine 32 (Sup32), Supervisor Engine 720 (Sup720), and Route Switch Processor 720 (RSP720) for multiple Cisco products, when using Multi Protocol Label Switching (MPLS) VPN and OSPF sham-link, allows remote attackers to cause a denial of service (blocked queue, device restart, or memory leak) via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:7600_router:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:catalyst_6500:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:me_6524_ethernet_switch:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:route_switch_processor:rsp720:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:supervisor_engine:sup32:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:supervisor_engine:sup720:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-27T10:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0538",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpip",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpip_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=120139657100513&w=2",
          "name" : "20080127 phpIP 4.3.2 - Numerous SQL Injection Vulnerablities",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28656",
          "name" : "28656",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487122/100/0/threaded",
          "name" : "20080127 phpIP 4.3.2 - Numerous SQL Injection Vulnerablities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27468",
          "name" : "27468",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0346",
          "name" : "ADV-2008-0346",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39965",
          "name" : "phpip-display-sql-injection(39965)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4990",
          "name" : "4990",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in phpIP Management 4.3.2 allow remote attackers to execute arbitrary SQL commands via the (1) password parameter to login.php, the (2) id parameter to display.php, and unspecified other vectors.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpip:phpip_management:4.3.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-01T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0539",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "f5",
            "product" : {
              "product_data" : [ {
                "product_name" : "tmos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.4.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28655",
          "name" : "28655",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3602",
          "name" : "3602",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487118/100/0/threaded",
          "name" : "20080126 F5 BIG-IP Web Management ASM Security Report XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489290/100/0/threaded",
          "name" : "20080308 F5 BIG-IP Web Management Console XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27462",
          "name" : "27462",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28151",
          "name" : "28151",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019276",
          "name" : "1019276",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0301",
          "name" : "ADV-2008-0301",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39979",
          "name" : "f5bigipwebmgmt-reprequest-xss(39979)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in dms/policy/rep_request.php in F5 BIG-IP Application Security Manager (ASM) 9.4.3 allows remote attackers to inject arbitrary web script or HTML via the report_type parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:f5:tmos:9.4.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-01T20:00Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0540",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "trixbox",
            "product" : {
              "product_data" : [ {
                "product_name" : "trixbox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.digitrustgroup.com/advisories/web-application-security-trixbox.html",
          "name" : "http://www.digitrustgroup.com/advisories/web-application-security-trixbox.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27460",
          "name" : "27460",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web script or HTML via the query string to index.php in (1) user/ or (2) maint/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trixbox:trixbox:2.4.2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-01T20:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0541",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gerd_tentler",
            "product" : {
              "product_data" : [ {
                "product_name" : "simple_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28681",
          "name" : "28681",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27463",
          "name" : "27463",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39978",
          "name" : "simpleforum-forum-xss(39978)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4989",
          "name" : "4989",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) open and (2) date_show parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gerd_tentler:simple_forum:3.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-01T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0542",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gerd_tentler",
            "product" : {
              "product_data" : [ {
                "product_name" : "simple_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28681",
          "name" : "28681",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27463",
          "name" : "27463",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39980",
          "name" : "simpleforum-thumbnail-directory-traversal(39980)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4989",
          "name" : "4989",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gerd_tentler:simple_forum:3.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-01T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0543",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pre_projects",
            "product" : {
              "product_data" : [ {
                "product_name" : "pre_dynamic_institution",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28651",
          "name" : "28651",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3603",
          "name" : "3603",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487054/100/0/threaded",
          "name" : "20080124 Pre Dynamic Institution bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27451",
          "name" : "27451",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39942",
          "name" : "predynamic-login-sql-injection(39942)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Pre Dynamic Institution allow remote attackers to execute arbitrary SQL commands via the (1) sloginid and (2) spass parameters to (a) login.asp and (b) siteadmin/login.asp.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pre_projects:pre_dynamic_institution:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-01T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0544",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sdl",
            "product" : {
              "product_data" : [ {
                "product_name" : "sdl_image",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=207933",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=207933",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28640",
          "name" : "28640",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28752",
          "name" : "28752",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28830",
          "name" : "28830",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28850",
          "name" : "28850",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28869",
          "name" : "28869",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29542",
          "name" : "29542",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0061",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0061",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1493",
          "name" : "DSA-1493",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200802-01.xml",
          "name" : "GLSA-200802-01",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.libsdl.org/cgi/viewvc.cgi/trunk/SDL_image/IMG_lbm.c?r1=3341&r2=3521",
          "name" : "http://www.libsdl.org/cgi/viewvc.cgi/trunk/SDL_image/IMG_lbm.c?r1=3341&r2=3521",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.libsdl.org/cgi/viewvc.cgi/trunk/SDL_image/IMG_lbm.c?revision=3521&view=markup",
          "name" : "http://www.libsdl.org/cgi/viewvc.cgi/trunk/SDL_image/IMG_lbm.c?revision=3521&view=markup",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:040",
          "name" : "MDVSA-2008:040",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488079/100/0/threaded",
          "name" : "20080213 rPSA-2008-0061-1 SDL_image",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27435",
          "name" : "27435",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-595-1",
          "name" : "USN-595-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0266",
          "name" : "ADV-2008-0266",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39899",
          "name" : "sdlimage-imgloadlbmrw-bo(39899)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2206",
          "name" : "https://issues.rpath.com/browse/RPL-2206",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00008.html",
          "name" : "FEDORA-2008-1208",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00039.html",
          "name" : "FEDORA-2008-1231",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the IMG_LoadLBM_RW function in IMG_lbm.c in SDL_image before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted IFF ILBM file.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sdl:sdl_image:1.2.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-01T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0545",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bubbling_library",
            "product" : {
              "product_data" : [ {
                "product_name" : "bubbling_library",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.32",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27466",
          "name" : "27466",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0347",
          "name" : "ADV-2008-0347",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39969",
          "name" : "bubblinglibrary-page-uri-file-include(39969)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4991",
          "name" : "4991",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) uri parameter to (a) yui-menu.tpl.php, (b) simple.tpl.php, and (c) advanced.tpl.php in dispatcher/framework/; and the (2) page parameter to (d) yui-menu.php, (e) simple.php, and (f) advanced.php in dispatcher/framework/, different vectors than CVE-2008-0521."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bubbling_library:bubbling_library:1.32:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-01T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0546",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "shoppingtree",
            "product" : {
              "product_data" : [ {
                "product_name" : "candypress_store",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1.26",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28662",
          "name" : "28662",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3600",
          "name" : "3600",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&PN=1",
          "name" : "http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&PN=1",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487058/100/0/threaded",
          "name" : "20080125 [CandyPress] eCommerce suite (SQL Injection + XSS + Path Disclosure)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27454",
          "name" : "27454",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0314",
          "name" : "ADV-2008-0314",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39939",
          "name" : "ecommercesuite-ajaxgetbrands-sql-injection(39939)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4988",
          "name" : "4988",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idProduct and (2) options parameters to (a) ajax/ajax_optInventory.asp, or the (2) recid parameter to (b) ajax/ajax_getBrands.asp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shoppingtree:candypress_store:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shoppingtree:candypress_store:4.1.1.26:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-01T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0547",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "shoppingtree",
            "product" : {
              "product_data" : [ {
                "product_name" : "candypress_store",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1.26",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28662",
          "name" : "28662",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3600",
          "name" : "3600",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&PN=1",
          "name" : "http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&PN=1",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487058/100/0/threaded",
          "name" : "20080125 [CandyPress] eCommerce suite (SQL Injection + XSS + Path Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27454",
          "name" : "27454",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0314",
          "name" : "ADV-2008-0314",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39940",
          "name" : "ecommercesuite-utilitiesconfighelp-xss(39940)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4988",
          "name" : "4988",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably earlier 4.x and 3.x versions, allows remote attackers to inject arbitrary web script or HTML via the helpfield parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shoppingtree:candypress_store:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shoppingtree:candypress_store:4.1.1.26:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-01T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0548",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "radio_toolbox",
            "product" : {
              "product_data" : [ {
                "product_name" : "steamcast",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.75",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/steamcazz-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/steamcazz-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39927",
          "name" : "steamcast-contentlength-dos(39927)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL dereference when malloc fails."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:radio_toolbox:steamcast:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.9.75"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-01T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0549",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "radio_toolbox",
            "product" : {
              "product_data" : [ {
                "product_name" : "steamcast",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.75",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/steamcazz-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/steamcazz-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://aluigi.org/poc/steamcazz.zip",
          "name" : "http://aluigi.org/poc/steamcazz.zip",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39929",
          "name" : "steamcast-oggheaderparse-dos(39929)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in the OggHeaderParse function in Steamcast 0.9.75 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via a long Ogg tag."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:radio_toolbox:steamcast:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.9.75"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-01T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0550",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "radio_toolbox",
            "product" : {
              "product_data" : [ {
                "product_name" : "steamcast",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.75",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/steamcazz-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/steamcazz-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://aluigi.org/poc/steamcazz.zip",
          "name" : "http://aluigi.org/poc/steamcazz.zip",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39928",
          "name" : "steamcast-http-bo(39928)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a certain HTTP request that leads to a buffer overflow, as demonstrated by a long User-Agent header."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:radio_toolbox:steamcast:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.9.75"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-01T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0551",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "activex",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "sejoong_namo",
            "product" : {
              "product_data" : [ {
                "product_name" : "activesquare",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28649",
          "name" : "28649",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27453",
          "name" : "27453",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27580",
          "name" : "27580",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0299",
          "name" : "ADV-2008-0299",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39943",
          "name" : "activesquare-namoinstaller-code-execution(39943)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39974",
          "name" : "namoinstaller-namoinstaller-code-execution(39974)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4986",
          "name" : "4986",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong Namo ActiveSquare 6 allows remote attackers to execute arbitrary code via a URL in the argument to the Install method.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:activex:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sejoong_namo:activesquare:6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-01T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0552",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "eticket",
            "product" : {
              "product_data" : [ {
                "product_name" : "eticket",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.6_rc4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3601",
          "name" : "3601",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.lonerunners.net/users/jekil/pub/hack-eticket/hack-eticket.txt",
          "name" : "http://www.lonerunners.net/users/jekil/pub/hack-eticket/hack-eticket.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487133/100/0/threaded",
          "name" : "20080127 eTicket 'index.php' Cross Site Scripting Path Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27473",
          "name" : "27473",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019278",
          "name" : "1019278",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39968",
          "name" : "eticket-index-xss(39968)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in eTicket 1.5.6-RC4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eticket:eticket:1.5.6_rc4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-01T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0553",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tcl_tk",
            "product" : {
              "product_data" : [ {
                "product_name" : "tcl_tk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6p2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0p2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.17",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "8.4a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4a3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4a4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4b1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4b2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5_a3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5a3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5a4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5a5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5a6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5b1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5b2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5b3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html",
          "name" : "SUSE-SR:2008:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28784",
          "name" : "28784",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28807",
          "name" : "28807",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28848",
          "name" : "28848",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28857",
          "name" : "28857",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28867",
          "name" : "28867",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28954",
          "name" : "28954",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29069",
          "name" : "29069",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29070",
          "name" : "29070",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29622",
          "name" : "29622",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30129",
          "name" : "30129",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30188",
          "name" : "30188",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30535",
          "name" : "30535",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30717",
          "name" : "30717",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30783",
          "name" : "30783",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/32608",
          "name" : "32608",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019309",
          "name" : "1019309",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=573933&group_id=10894",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=573933&group_id=10894",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-237465-1",
          "name" : "237465",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://ubuntu.com/usn/usn-664-1",
          "name" : "USN-664-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0054",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0054",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1490",
          "name" : "DSA-1490",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1491",
          "name" : "DSA-1491",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1598",
          "name" : "DSA-1598",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:041",
          "name" : "MDVSA-2008:041",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2008_13_sr.html",
          "name" : "SUSE-SR:2008:013",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0134.html",
          "name" : "RHSA-2008:0134",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0135.html",
          "name" : "RHSA-2008:0135",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0136.html",
          "name" : "RHSA-2008:0136",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488069/100/0/threaded",
          "name" : "20080212 rPSA-2008-0054-1 tk",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/493080/100/0/threaded",
          "name" : "20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27655",
          "name" : "27655",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vmware.com/security/advisories/VMSA-2008-0009.html",
          "name" : "http://www.vmware.com/security/advisories/VMSA-2008-0009.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0430",
          "name" : "ADV-2008-0430",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1456/references",
          "name" : "ADV-2008-1456",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1744",
          "name" : "ADV-2008-1744",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=431518",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=431518",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2215",
          "name" : "https://issues.rpath.com/browse/RPL-2215",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10098",
          "name" : "oval:org.mitre.oval:def:10098",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00115.html",
          "name" : "FEDORA-2008-1323",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00132.html",
          "name" : "FEDORA-2008-1131",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00193.html",
          "name" : "FEDORA-2008-1122",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00205.html",
          "name" : "FEDORA-2008-1384",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00116.html",
          "name" : "FEDORA-2008-3545",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the ReadImage function in tkImgGIF.c in Tk (Tcl/Tk) before 8.5.1 allows remote attackers to execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4484."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:4.0p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:6.1p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:7.5p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:7.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:7.6p2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.0p2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.4.17"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4a3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4a4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4b1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.4b2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.5_a3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.5a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.5a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.5a3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.5a4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.5a5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.5a6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.5b1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.5b2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tcl_tk:tcl_tk:8.5b3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0554",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "netpbm",
            "product" : {
              "product_data" : [ {
                "product_name" : "netpbm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.26",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464056",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464056",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29079",
          "name" : "29079",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30280",
          "name" : "30280",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32607",
          "name" : "32607",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://ubuntu.com/usn/usn-665-1",
          "name" : "USN-665-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1579",
          "name" : "DSA-1579",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:039",
          "name" : "MDVSA-2008:039",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0131.html",
          "name" : "RHSA-2008:0131",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27682",
          "name" : "27682",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019358",
          "name" : "1019358",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0460",
          "name" : "ADV-2008-0460",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2216",
          "name" : "https://issues.rpath.com/browse/RPL-2216",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10975",
          "name" : "oval:org.mitre.oval:def:10975",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the readImageData function in giftopnm.c in netpbm before 10.27 in netpbm before 10.27 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4484."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netpbm:netpbm:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "10.26"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-08T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0555",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache-ssl",
            "product" : {
              "product_data" : [ {
                "product_name" : "apache-ssl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.34_1.57",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          }, {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29644",
          "name" : "29644",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3797",
          "name" : "3797",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.apache-ssl.org/advisory-cve-2008-0555.txt",
          "name" : "http://www.apache-ssl.org/advisory-cve-2008-0555.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.cynops.de/advisories/CVE-2008-0555.txt",
          "name" : "http://www.cynops.de/advisories/CVE-2008-0555.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.klink.name/security/aklink-sa-2008-005-apache-ssl.txt",
          "name" : "http://www.klink.name/security/aklink-sa-2008-005-apache-ssl.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/490386/100/0/threaded",
          "name" : "20080402 ANNOUNCE: Apache-SSL security release - apache_1.3.41+ssl_1.59",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28576",
          "name" : "28576",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019784",
          "name" : "1019784",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1079/references",
          "name" : "ADV-2008-1079",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41618",
          "name" : "apachessl-expandcert-information-disclosure(41618)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (DN) in a client certificate, which might allow remote attackers to bypass authentication via a crafted DN that triggers overwriting of environment variables."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache-ssl:apache-ssl:1.3.34_1.57:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-04T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0556",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openca",
            "product" : {
              "product_data" : [ {
                "product_name" : "openca_pki",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.2.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          }, {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060300.html",
          "name" : "20080213 OpenCA XSRF (CVE-2008-0556)",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28951",
          "name" : "28951",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019426",
          "name" : "1019426",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/264385",
          "name" : "VU#264385",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0588",
          "name" : "ADV-2008-0588",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40476",
          "name" : "openca-certificate-csrf(40476)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.cynops.de/advisories/CVE-2008-0556.txt",
          "name" : "https://www.cynops.de/advisories/CVE-2008-0556.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in OpenCA PKI 0.9.2.5, and possibly earlier versions, allows remote attackers to perform unauthorized actions as authorized users via a link or IMG tag to RAServer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openca:openca_pki:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.9.2.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T00:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0557",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mamboserver",
            "product" : {
              "product_data" : [ {
                "product_name" : "catalogshop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0b1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27558",
          "name" : "27558",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40142",
          "name" : "catalogshop-index-sql-injection(40142)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5030",
          "name" : "5030",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the CatalogShop (com_catalogshop) 1.0b1 componenent for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mamboserver:catalogshop:1.0b1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-04T23:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0558",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "uniwin",
            "product" : {
              "product_data" : [ {
                "product_name" : "ecart_professional",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28735",
          "name" : "28735",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27560",
          "name" : "27560",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Uniwin eCart Professional before 2.0.16 allows remote attackers to inject arbitrary web script or HTML via the rp parameter to cartView.asp and unspecified other components.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uniwin:ecart_professional:2.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uniwin:ecart_professional:2.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uniwin:ecart_professional:2.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uniwin:ecart_professional:2.0.15:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-04T23:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0559",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nilsons_blogger",
            "product" : {
              "product_data" : [ {
                "product_name" : "nilsons_blogger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28737",
          "name" : "28737",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3604",
          "name" : "3604",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487384/100/0/threaded",
          "name" : "20080131 nilson's blogger 0.11 remote file disclosure vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27559",
          "name" : "27559",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in Nilson's Blogger 0.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the permalink parameter in core.php, accessed through index.php; and (2) the thispost parameter in comments.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nilsons_blogger:nilsons_blogger:0.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-04T23:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0560",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "contact_forms",
            "product" : {
              "product_data" : [ {
                "product_name" : "cforms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3605",
          "name" : "3605",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2008-January/001895.html",
          "name" : "20080131 [Fwd: contactforms \"cforms-css.php\" Remote File Inclusion]",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487347/100/0/threaded",
          "name" : "20080131 contactforms \"cforms-css.php\" Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40143",
          "name" : "contactform-cformscss-file-include(40143)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  PHP remote file inclusion vulnerability in cforms-css.php in Oliver Seidel cforms (contactforms), a Wordpress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the tm parameter. NOTE: CVE disputes this issue for 7.3, since there is no tm parameter, and the code exits with a fatal error due to a call to an undefined function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:contact_forms:cforms:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-04T23:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0561",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "arthur_konze_webdesign",
            "product" : {
              "product_data" : [ {
                "product_name" : "akogallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "joomla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "mambo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27557",
          "name" : "27557",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40141",
          "name" : "akogallery-index-sql-injection(40141)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5029",
          "name" : "5029",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Arthur Konze AkoGallery (com_akogallery) 2.5 beta component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:arthur_konze_webdesign:akogallery:2.5_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-04T23:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0562",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mamboserver",
            "product" : {
              "product_data" : [ {
                "product_name" : "joomla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mambo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27551",
          "name" : "27551",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40144",
          "name" : "restaurant-index-sql-injection(40144)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5031",
          "name" : "5031",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Restaurant (com_restaurant) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mamboserver:joomla:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mamboserver:mambo:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-04T23:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0563",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "liferay",
            "product" : {
              "product_data" : [ {
                "product_name" : "liferay_enterprise_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://support.liferay.com/browse/LEP-4737",
          "name" : "http://support.liferay.com/browse/LEP-4737",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to perform unspecified actions as unspecified authenticated users via the User-Agent HTTP header, which is used when composing Forgot Password e-mail messages in HTML format."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:liferay:liferay_enterprise_portal:4.3.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-05T00:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0564",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mailman",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailman",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.10b",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html",
          "name" : "APPLE-SA-2010-03-29-1",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html",
          "name" : "SUSE-SR:2008:017",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://mail.python.org/pipermail/mailman-announce/2008-February/000096.html",
          "name" : "[Mailman-Announce] 20080203 Mailman 2.1.10b3 Released (was: Re: Mailman 2.1.10b1 Released)",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28794",
          "name" : "28794",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28916",
          "name" : "28916",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28966",
          "name" : "28966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29249",
          "name" : "29249",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29388",
          "name" : "29388",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31687",
          "name" : "31687",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/43549",
          "name" : "43549",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=559308&group_id=103",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=559308&group_id=103",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT4077",
          "name" : "http://support.apple.com/kb/HT4077",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0056",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0056",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:061",
          "name" : "MDVSA-2008:061",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2011-0307.html",
          "name" : "RHSA-2011:0307",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488236/100/0/threaded",
          "name" : "20080215 rPSA-2008-0056-1 mailman",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27630",
          "name" : "27630",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-586-1",
          "name" : "USN-586-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0422",
          "name" : "ADV-2008-0422",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2011/0542",
          "name" : "ADV-2011-0542",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=431526",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=431526",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2207",
          "name" : "https://issues.rpath.com/browse/RPL-2207",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00452.html",
          "name" : "FEDORA-2008-1334",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) editing templates and (2) the list's \"info attribute\" in the web administrator interface, a different vulnerability than CVE-2006-3636."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailman:mailman:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1.10b"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-05T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0565",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "deltascripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_links",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/40840",
          "name" : "40840",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28727",
          "name" : "28727",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27530",
          "name" : "27530",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5021",
          "name" : "5021",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:deltascripts:php_links:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0566",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "deltascripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_links",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27529",
          "name" : "27529",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5022",
          "name" : "5022",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in includes/smarty.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path_to_public_program parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:deltascripts:php_links:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0567",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "chronoengine",
            "product" : {
              "product_data" : [ {
                "product_name" : "chronoforms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27531",
          "name" : "27531",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5020",
          "name" : "5020",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) PPS/File.php, (2) Writer.php, and (3) PPS.php in excelwriter/; and (4) BIFFwriter.php, (5) Workbook.php, (6) Worksheet.php, and (7) Format.php in excelwriter/Writer/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:chronoengine:chronoforms:2.3.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0568",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "secure_site_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/216019",
          "name" : "http://drupal.org/node/216019",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28732",
          "name" : "28732",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27543",
          "name" : "27543",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0377/references",
          "name" : "ADV-2008-0377",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attackers to gain the privileges of a user who has authenticated from behind the same proxy server as the attacker."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:secure_site_module:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:secure_site_module:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T02:00Z",
    "lastModifiedDate" : "2011-03-08T03:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0569",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "comment_upload_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/216024",
          "name" : "http://drupal.org/node/216024",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://drupal.org/node/216035",
          "name" : "http://drupal.org/node/216035",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://drupal.org/node/216036",
          "name" : "http://drupal.org/node/216036",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28729",
          "name" : "28729",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27544",
          "name" : "27544",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0374/references",
          "name" : "ADV-2008-0374",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Comment Upload 4.7.x before 4.7.x-0.1 and 5.x before 5.x-0.1 module for Drupal does not properly use functions in the upload module, which allows remote attackers to bypass upload validation, and upload arbitrary files and possibly execute arbitrary code, via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:comment_upload_module:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:comment_upload_module:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T02:00Z",
    "lastModifiedDate" : "2011-03-08T03:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0570",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "openid",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/216022",
          "name" : "http://drupal.org/node/216022",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28717",
          "name" : "28717",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27542",
          "name" : "27542",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0373/references",
          "name" : "ADV-2008-0373",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The OpenID 5.x-1.0 and earlier module for Drupal does not properly verify the claimed_id returned by an OpenID provider, which allows remote OpenID providers to spoof OpenID authentication for domains associated with other providers."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:openid:5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T02:00Z",
    "lastModifiedDate" : "2011-03-08T03:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0571",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "userpoints_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/216023",
          "name" : "http://drupal.org/node/216023",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28730",
          "name" : "28730",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0375/references",
          "name" : "ADV-2008-0375",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The point moderation form in the Userpoints 4.7.x before 4.7.x-2.3, 5.x-2 before 5.x-2.16, and 5.x-3 before 5.x-3.3 module for Drupal does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and manipulate points."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:userpoints_module:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:userpoints_module:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-05T02:00Z",
    "lastModifiedDate" : "2011-03-08T03:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0572",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mindmeld",
            "product" : {
              "product_data" : [ {
                "product_name" : "mindmeld",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.0.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27538",
          "name" : "27538",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5026",
          "name" : "5026",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in Mindmeld 1.2.0.10 allow remote attackers to execute arbitrary PHP code via a URL in the MM_GLOBALS[home] parameter to (1) acweb/admin_index.php; and (2) ask.inc.php, (3) learn.inc.php, (4) manage.inc.php, (5) mind.inc.php, and (6) sensory.inc.php in include/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mindmeld:mindmeld:1.2.0.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0573",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "safenet",
            "product" : {
              "product_data" : [ {
                "product_name" : "ipsecdrv.sys",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.0.12",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "safenet_highassurance_remote",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.12",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "softremote_vpn_client",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28701",
          "name" : "28701",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27496",
          "name" : "27496",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019282",
          "name" : "1019282",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0333",
          "name" : "ADV-2008-0333",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5004",
          "name" : "5004",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafted IPSECDRV_IOCTL IOCTL request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:safenet:ipsecdrv.sys:10.4.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:safenet:safenet_highassurance_remote:1.4.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:safenet:softremote_vpn_client:1.4.12:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0574",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webspell",
            "product" : {
              "product_data" : [ {
                "product_name" : "webspell",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.01.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28684",
          "name" : "28684",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3606",
          "name" : "3606",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487312/100/0/threaded",
          "name" : "20080130 Webspell 4.01.02 2 Vulnerabilites",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27517",
          "name" : "27517",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40084",
          "name" : "webspell-index-xss(40084)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.01.02 allows remote attackers to inject arbitrary web script or HTML via the sort parameter in a whoisonline action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webspell:webspell:4.01.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-05T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0575",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webspell",
            "product" : {
              "product_data" : [ {
                "product_name" : "webspell",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.01.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28684",
          "name" : "28684",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3606",
          "name" : "3606",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487312/100/0/threaded",
          "name" : "20080130 Webspell 4.01.02 2 Vulnerabilites",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote attackers to assign the superadmin privilege level to arbitrary accounts as administrators via an \"update member\" action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webspell:webspell:4.01.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-05T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0576",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "project_issue_tracking_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/216062",
          "name" : "http://drupal.org/node/216062",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28731",
          "name" : "28731",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0376/references",
          "name" : "ADV-2008-0376",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier in the 4.7.x-2.x series, and 4.7.x-1.6 and earlier in the 4.7.x-1.x series for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors that write to summary table pages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project_issue_tracking_module:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project_issue_tracking_module:5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-05T02:00Z",
    "lastModifiedDate" : "2011-03-08T03:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0577",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "project_issue_tracking_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/216063",
          "name" : "http://drupal.org/node/216063",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28731",
          "name" : "28731",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0376/references",
          "name" : "ADV-2008-0376",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier in the 4.7.x-2.x series, and 4.7.x-1.6 and earlier in the 4.7.x-1.x series for Drupal (1) does not restrict the extensions of attached files when the Upload module is enabled for issue nodes, which allows remote attackers to upload and possibly execute arbitrary files; and (2) accepts the .html extension within the bundled file-upload functionality, which allows remote attackers to upload files containing arbitrary web script or HTML."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project_issue_tracking_module:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project_issue_tracking_module:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T02:00Z",
    "lastModifiedDate" : "2011-03-08T03:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0578",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tripwire",
            "product" : {
              "product_data" : [ {
                "product_name" : "tripwire_enterprise",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28687",
          "name" : "28687",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3610",
          "name" : "3610",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.liquidmatrix.org/blog/2008/01/29/advisory-tripwire-enterprise-xss-vulnerability",
          "name" : "http://www.liquidmatrix.org/blog/2008/01/29/advisory-tripwire-enterprise-xss-vulnerability",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487229/100/0/threaded",
          "name" : "20080129 Advisory: Tripwire Enterprise/Server XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27486",
          "name" : "27486",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019279",
          "name" : "1019279",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0372/references",
          "name" : "ADV-2008-0372",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40016",
          "name" : "tripwire-login-xss(40016)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the web management login page in Tripwire Enterprise 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tripwire:tripwire_enterprise:7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-05T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0579",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_buslicense",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27508",
          "name" : "27508",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0359/references",
          "name" : "ADV-2008-0359",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5011",
          "name" : "5011",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the buslicense (com_buslicense) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in a list action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_buslicense:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T03:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0580",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "geert_moernaut",
            "product" : {
              "product_data" : [ {
                "product_name" : "lsrunase",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "supercrypt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3611",
          "name" : "3611",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487269/100/0/threaded",
          "name" : "20080129 Insecure Use of RC4 in LSrunasE and Supercrypt (CVE-2007-6340)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27500",
          "name" : "27500",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Geert Moernaut LSrunasE and Supercrypt use an encryption key composed of an SHA1 hash of a fixed string embedded in the executable file, which makes it easier for local users to obtain this key without reverse engineering."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geert_moernaut:lsrunase:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geert_moernaut:supercrypt:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T03:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0581",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "moernaut",
            "product" : {
              "product_data" : [ {
                "product_name" : "lsrunase",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "supercrypt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3611",
          "name" : "3611",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487269/100/0/threaded",
          "name" : "20080129 Insecure Use of RC4 in LSrunasE and Supercrypt (CVE-2007-6340)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Geert Moernaut LSrunasE allows local users to gain privileges by obtaining the encrypted password from a batch file, and constructing a modified batch file that specifies this password in the /password switch and specifies an arbitrary program in the /command switch."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moernaut:lsrunase:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moernaut:supercrypt:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T03:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0582",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "skype_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "skype",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.0.244",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aviv.raffon.net/2008/01/31/AttackersCanSkypeFindYou.aspx",
          "name" : "http://aviv.raffon.net/2008/01/31/AttackersCanSkypeFindYou.aspx",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/794236",
          "name" : "VU#794236",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487370/100/0/threaded",
          "name" : "20080131 Attackers can SkypeFind you",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27338",
          "name" : "27338",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.1 through 3.6.0.244 on Windows allows remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Full Name field of a reviewer of a business item entry, accessible through (1) the SkypeFind dialog and (2) a skype:?skypefind URI for the skype: URI handler."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:skype_technologies:skype:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:skype_technologies:skype:3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:skype_technologies:skype:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:skype_technologies:skype:3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:skype_technologies:skype:3.6.0.244:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-05T03:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0583",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "skype_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "skype",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.216",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.244",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aviv.raffon.net/2008/01/22/NoMoreVideosForYouComeBackWhenPatchAvailable.aspx",
          "name" : "http://aviv.raffon.net/2008/01/22/NoMoreVideosForYouComeBackWhenPatchAvailable.aspx",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://skype.com/security/skype-sb-2008-001-update1.htm",
          "name" : "http://skype.com/security/skype-sb-2008-001-update1.htm",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/794236",
          "name" : "VU#794236",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27338",
          "name" : "27338",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39754",
          "name" : "skype-addvideotochat-code-execution(39754)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Description and unspecified other metadata fields of a Metacafe movie submitted by Metacafe Pro to the Skype video gallery, accessible through a search within the (1) \"Add video to chat\" or (2) \"Add video to mood\" dialog, a different vector than CVE-2008-0454."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:skype_technologies:skype:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:skype_technologies:skype:3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:skype_technologies:skype:3.6.216:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:skype_technologies:skype:3.6.244:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-05T03:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0584",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28609",
          "name" : "28609",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IY96095",
          "name" : "IY96095",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IY96101",
          "name" : "IY96101",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27432",
          "name" : "27432",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0261",
          "name" : "ADV-2008-0261",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4064",
          "name" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4064",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5744",
          "name" : "oval:org.mitre.oval:def:5744",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) swap, (2) swapoff, and (3) swapon programs."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T03:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0585",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28609",
          "name" : "28609",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IY97257",
          "name" : "IY97257",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27433",
          "name" : "27433",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0261",
          "name" : "ADV-2008-0261",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4066",
          "name" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4066",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39906",
          "name" : "aix-websm-insecure-permissions(39906)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to \"alter the behavior of\" this client by overwriting these files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T03:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0586",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aix.software.ibm.com/aix/efixes/security/lvm_advisory.asc",
          "name" : "http://aix.software.ibm.com/aix/efixes/security/lvm_advisory.asc",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/40427",
          "name" : "40427",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/40428",
          "name" : "40428",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/40429",
          "name" : "40429",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28609",
          "name" : "28609",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IY98331",
          "name" : "IY98331",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IY98340",
          "name" : "IY98340",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IY99537",
          "name" : "IY99537",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IZ00559",
          "name" : "IZ00559",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IZ10828",
          "name" : "IZ10828",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27431",
          "name" : "27431",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0261",
          "name" : "ADV-2008-0261",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=isg1IY98448",
          "name" : "IY98448",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=isg1IY98450",
          "name" : "IY98450",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4068",
          "name" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4068",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39907",
          "name" : "aix-lvm-commands-bo(39907)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5704",
          "name" : "oval:org.mitre.oval:def:5704",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) lchangevg, (2) ldeletepv, (3) putlvodm, (4) lvaryoffvg, and (5) lvgenminor programs in bos.rte.lvm; and the (6) tellclvmd program in bos.clvm.enh."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T03:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0587",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28609",
          "name" : "28609",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IZ06261",
          "name" : "IZ06261",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IZ06489",
          "name" : "IZ06489",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IZ06621",
          "name" : "IZ06621",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27429",
          "name" : "27429",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0261",
          "name" : "ADV-2008-0261",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4072",
          "name" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4072",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39910",
          "name" : "aix-uspchrp-bo(39910)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5686",
          "name" : "oval:org.mitre.oval:def:5686",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the uspchrp program in devices.chrp.base.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T03:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0588",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28609",
          "name" : "28609",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IZ06260",
          "name" : "IZ06260",
          "refsource" : "AIXAPAR",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IZ06488",
          "name" : "IZ06488",
          "refsource" : "AIXAPAR",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IZ06620",
          "name" : "IZ06620",
          "refsource" : "AIXAPAR",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27430",
          "name" : "27430",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0261",
          "name" : "ADV-2008-0261",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4070",
          "name" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4070",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39909",
          "name" : "aix-utape-bo(39909)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5572",
          "name" : "oval:org.mitre.oval:def:5572",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the utape program in devices.scsi.tape.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T03:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0589",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28609",
          "name" : "28609",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019265",
          "name" : "1019265",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IZ11242",
          "name" : "IZ11242",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IZ11243",
          "name" : "IZ11243",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IZ11244",
          "name" : "IZ11244",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=isg1IZ12745",
          "name" : "IZ12745",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27434",
          "name" : "27434",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0261",
          "name" : "ADV-2008-0261",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4075",
          "name" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4075",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39911",
          "name" : "aix-ps-information-disclosure(39911)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ps program in bos.rte.control in IBM AIX 5.2, 5.3, and 6.1 allows local users to obtain sensitive information via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T03:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0590",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "progress",
            "product" : {
              "product_data" : [ {
                "product_name" : "ipswitch_ws_ftp_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28753",
          "name" : "28753",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3609",
          "name" : "3609",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487441/100/0/threaded",
          "name" : "20080202 IpSwitch WS_FTPSERVER with SSH remote Buffer Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27573",
          "name" : "27573",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0400/references",
          "name" : "ADV-2008-0400",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5044",
          "name" : "5044",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long opendir command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:progress:ipswitch_ws_ftp_server:6.1.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-05T12:00Z",
    "lastModifiedDate" : "2019-08-13T14:40Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0591",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-06/0026.html",
          "name" : "20070604 Assorted browser vulnerabilities",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://browser.netscape.com/releasenotes/",
          "name" : "http://browser.netscape.com/releasenotes/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lcamtuf.coredump.cx/ffclick2/",
          "name" : "http://lcamtuf.coredump.cx/ffclick2/",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html",
          "name" : "SUSE-SA:2008:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28754",
          "name" : "28754",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28758",
          "name" : "28758",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28766",
          "name" : "28766",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28808",
          "name" : "28808",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28818",
          "name" : "28818",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28839",
          "name" : "28839",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28864",
          "name" : "28864",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28865",
          "name" : "28865",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28877",
          "name" : "28877",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28879",
          "name" : "28879",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28924",
          "name" : "28924",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28939",
          "name" : "28939",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28958",
          "name" : "28958",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29049",
          "name" : "29049",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29086",
          "name" : "29086",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29164",
          "name" : "29164",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29167",
          "name" : "29167",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29567",
          "name" : "29567",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30327",
          "name" : "30327",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30620",
          "name" : "30620",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2781",
          "name" : "2781",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1",
          "name" : "238492",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "name" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0093",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0093",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1484",
          "name" : "DSA-1484",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1485",
          "name" : "DSA-1485",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1489",
          "name" : "DSA-1489",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1506",
          "name" : "DSA-1506",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml",
          "name" : "GLSA-200805-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:048",
          "name" : "MDVSA-2008:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:062",
          "name" : "MDVSA-2008:062",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-08.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-08.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0103.html",
          "name" : "RHSA-2008:0103",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0104.html",
          "name" : "RHSA-2008:0104",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0105.html",
          "name" : "RHSA-2008:0105",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/470446/100/0/threaded",
          "name" : "20070604 Assorted browser vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487826/100/0/threaded",
          "name" : "20080209 rPSA-2008-0051-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488002/100/0/threaded",
          "name" : "20080212 FLEA-2008-0001-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488971/100/0/threaded",
          "name" : "20080229 rPSA-2008-0093-1 thunderbird",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24293",
          "name" : "24293",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27683",
          "name" : "27683",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019339",
          "name" : "1019339",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-576-1",
          "name" : "USN-576-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0453/references",
          "name" : "ADV-2008-0453",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0454/references",
          "name" : "ADV-2008-0454",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0627/references",
          "name" : "ADV-2008-0627",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1793/references",
          "name" : "ADV-2008-1793",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=376473",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=376473",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1995",
          "name" : "https://issues.rpath.com/browse/RPL-1995",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10900",
          "name" : "oval:org.mitre.oval:def:10900",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html",
          "name" : "FEDORA-2008-1435",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html",
          "name" : "FEDORA-2008-1459",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html",
          "name" : "FEDORA-2008-1535",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html",
          "name" : "FEDORA-2008-2060",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html",
          "name" : "FEDORA-2008-2118",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by using a timer to change the window focus, aka the \"dialog refocus bug\" or \"ffclick2\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-09T00:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0592",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://browser.netscape.com/releasenotes/",
          "name" : "http://browser.netscape.com/releasenotes/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html",
          "name" : "SUSE-SA:2008:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28754",
          "name" : "28754",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28818",
          "name" : "28818",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28864",
          "name" : "28864",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28865",
          "name" : "28865",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28877",
          "name" : "28877",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28879",
          "name" : "28879",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28924",
          "name" : "28924",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28939",
          "name" : "28939",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28958",
          "name" : "28958",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29086",
          "name" : "29086",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29167",
          "name" : "29167",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29567",
          "name" : "29567",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30327",
          "name" : "30327",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30620",
          "name" : "30620",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1",
          "name" : "238492",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "name" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1484",
          "name" : "DSA-1484",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1485",
          "name" : "DSA-1485",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1489",
          "name" : "DSA-1489",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1506",
          "name" : "DSA-1506",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml",
          "name" : "GLSA-200805-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:048",
          "name" : "MDVSA-2008:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-09.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-09.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0103.html",
          "name" : "RHSA-2008:0103",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0104.html",
          "name" : "RHSA-2008:0104",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0105.html",
          "name" : "RHSA-2008:0105",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487826/100/0/threaded",
          "name" : "20080209 rPSA-2008-0051-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488002/100/0/threaded",
          "name" : "20080212 FLEA-2008-0001-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27683",
          "name" : "27683",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019340",
          "name" : "1019340",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-576-1",
          "name" : "USN-576-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0453/references",
          "name" : "ADV-2008-0453",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0627/references",
          "name" : "ADV-2008-0627",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1793/references",
          "name" : "ADV-2008-1793",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=387258",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=387258",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9972",
          "name" : "oval:org.mitre.oval:def:9972",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html",
          "name" : "FEDORA-2008-1435",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html",
          "name" : "FEDORA-2008-1459",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html",
          "name" : "FEDORA-2008-1535",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html",
          "name" : "FEDORA-2008-2060",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html",
          "name" : "FEDORA-2008-2118",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to cause a denial of service via a plain .txt file with a \"Content-Disposition: attachment\" and an invalid \"Content-Type: plain/text,\" which prevents Firefox from rendering future plain text files within the browser."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-09T00:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0593",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.99",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.17",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://browser.netscape.com/releasenotes/",
          "name" : "http://browser.netscape.com/releasenotes/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html",
          "name" : "SUSE-SA:2008:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28754",
          "name" : "28754",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28758",
          "name" : "28758",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28766",
          "name" : "28766",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28815",
          "name" : "28815",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28818",
          "name" : "28818",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28839",
          "name" : "28839",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28864",
          "name" : "28864",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28865",
          "name" : "28865",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28877",
          "name" : "28877",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28879",
          "name" : "28879",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28924",
          "name" : "28924",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28939",
          "name" : "28939",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28958",
          "name" : "28958",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29049",
          "name" : "29049",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29086",
          "name" : "29086",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29167",
          "name" : "29167",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29567",
          "name" : "29567",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30327",
          "name" : "30327",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30620",
          "name" : "30620",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1",
          "name" : "238492",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "name" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1484",
          "name" : "DSA-1484",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1485",
          "name" : "DSA-1485",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1489",
          "name" : "DSA-1489",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1506",
          "name" : "DSA-1506",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml",
          "name" : "GLSA-200805-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:048",
          "name" : "MDVSA-2008:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-10.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-10.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0103.html",
          "name" : "RHSA-2008:0103",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0104.html",
          "name" : "RHSA-2008:0104",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0105.html",
          "name" : "RHSA-2008:0105",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487826/100/0/threaded",
          "name" : "20080209 rPSA-2008-0051-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27683",
          "name" : "27683",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019341",
          "name" : "1019341",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-576-1",
          "name" : "USN-576-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0453/references",
          "name" : "ADV-2008-0453",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0627/references",
          "name" : "ADV-2008-0627",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1793/references",
          "name" : "ADV-2008-1793",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=397427",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=397427",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10075",
          "name" : "oval:org.mitre.oval:def:10075",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html",
          "name" : "FEDORA-2008-1435",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html",
          "name" : "FEDORA-2008-1459",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html",
          "name" : "FEDORA-2008-1535",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html",
          "name" : "FEDORA-2008-2060",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html",
          "name" : "FEDORA-2008-2118",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypass the Same Origin Policy and read sensitive information from the original URL, such as with Single-Signon systems."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:beta:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:dev:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.99:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.1.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.17"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-09T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0594",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://browser.netscape.com/releasenotes/",
          "name" : "http://browser.netscape.com/releasenotes/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html",
          "name" : "SUSE-SA:2008:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28864",
          "name" : "28864",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28865",
          "name" : "28865",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28877",
          "name" : "28877",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28879",
          "name" : "28879",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28924",
          "name" : "28924",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28939",
          "name" : "28939",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28958",
          "name" : "28958",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29086",
          "name" : "29086",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29567",
          "name" : "29567",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30327",
          "name" : "30327",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30620",
          "name" : "30620",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1",
          "name" : "238492",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "name" : "http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0051",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1484",
          "name" : "DSA-1484",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1485",
          "name" : "DSA-1485",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1489",
          "name" : "DSA-1489",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1506",
          "name" : "DSA-1506",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml",
          "name" : "GLSA-200805-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:048",
          "name" : "MDVSA-2008:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2008/mfsa2008-11.html",
          "name" : "http://www.mozilla.org/security/announce/2008/mfsa2008-11.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487826/100/0/threaded",
          "name" : "20080209 rPSA-2008-0051-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488002/100/0/threaded",
          "name" : "20080212 FLEA-2008-0001-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27683",
          "name" : "27683",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019342",
          "name" : "1019342",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-576-1",
          "name" : "USN-576-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0453/references",
          "name" : "ADV-2008-0453",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0627/references",
          "name" : "ADV-2008-0627",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1793/references",
          "name" : "ADV-2008-1793",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=408164",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=408164",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html",
          "name" : "FEDORA-2008-1435",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html",
          "name" : "FEDORA-2008-1535",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Mozilla Firefox before 2.0.0.12 does not always display a web forgery warning dialog if the entire contents of a web page are in a DIV tag that uses absolute positioning, which makes it easier for remote attackers to conduct phishing attacks."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-09T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0595",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "d-bus",
            "product" : {
              "product_data" : [ {
                "product_name" : "inter-process_communication_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mandrakesoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "mandrake_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007.0_x86_64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2008.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "red_hat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "fedora",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.freedesktop.org/archives/dbus/2008-February/009401.html",
          "name" : "[dbus] 20080227 [ANNOUNCE] CVE-2008-0595 D-Bus Security Releases - D-Bus 1.0.3 and D-Bus 1.1.20",
          "refsource" : "MLIST",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html",
          "name" : "SUSE-SR:2008:006",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2012-10/msg00094.html",
          "name" : "openSUSE-SU-2012:1418",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29148",
          "name" : "29148",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29160",
          "name" : "29160",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29171",
          "name" : "29171",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29173",
          "name" : "29173",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29281",
          "name" : "29281",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29323",
          "name" : "29323",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30869",
          "name" : "30869",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32281",
          "name" : "32281",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019512",
          "name" : "1019512",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0099",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0099",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0099",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0099",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1599",
          "name" : "DSA-1599",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.j5live.com/2008/02/27/announce-d-bus-1120-conisten-water-released/",
          "name" : "http://www.j5live.com/2008/02/27/announce-d-bus-1120-conisten-water-released/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:054",
          "name" : "MDVSA-2008:054",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0159.html",
          "name" : "RHSA-2008:0159",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489280/100/0/threaded",
          "name" : "20080307 rPSA-2008-0099-1 dbus dbus-glib dbus-qt dbus-x11",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28023",
          "name" : "28023",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-653-1",
          "name" : "USN-653-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0694",
          "name" : "ADV-2008-0694",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2282",
          "name" : "https://issues.rpath.com/browse/RPL-2282",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9353",
          "name" : "oval:org.mitre.oval:def:9353",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00893.html",
          "name" : "FEDORA-2008-2043",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00911.html",
          "name" : "FEDORA-2008-2070",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:d-bus:inter-process_communication_system:0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:d-bus:inter-process_communication_system:0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:d-bus:inter-process_communication_system:0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:d-bus:inter-process_communication_system:0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:d-bus:inter-process_communication_system:0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:d-bus:inter-process_communication_system:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:d-bus:inter-process_communication_system:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:d-bus:inter-process_communication_system:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:d-bus:inter-process_communication_system:1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2007.0_x86_64:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2007.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2007.1:*:x86-64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2008.0:*:x86-64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:red_hat:enterprise_linux:5:*:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:red_hat:enterprise_linux_desktop:5:*:client:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:red_hat:enterprise_linux_desktop_workstation:5:*:client:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:fedora:7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-29T19:44Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0596",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "easy_software_products",
            "product" : {
              "product_data" : [ {
                "product_name" : "cups",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.22",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00000.html",
          "name" : "SUSE-SA:2008:012",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29087",
          "name" : "29087",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29189",
          "name" : "29189",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29251",
          "name" : "29251",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2008-084.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2008-084.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2008-098.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2008-098.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0091",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0091",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0091",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0091",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:050",
          "name" : "MDVSA-2008:050",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0153.html",
          "name" : "RHSA-2008:0153",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0161.html",
          "name" : "RHSA-2008:0161",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488966/100/0/threaded",
          "name" : "20080229 rPSA-2008-0091-1 cups",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27988",
          "name" : "27988",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019497",
          "name" : "1019497",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40842",
          "name" : "cups-ippbrowse-memoryleak-dos(40842)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2283",
          "name" : "https://issues.rpath.com/browse/RPL-2283",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10857",
          "name" : "oval:org.mitre.oval:def:10857",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Memory leak in CUPS before 1.1.22, and possibly other versions, allows remote attackers to cause a denial of service (memory consumption and daemon crash) via a large number of requests to add and remove shared printers."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:desktop:3.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:desktop:4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:as_3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:as_4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:es_3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:es_4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:ws_3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:ws_4:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:easy_software_products:cups:1.1.17:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:easy_software_products:cups:1.1.22:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-26T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0597",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "easy_software_products",
            "product" : {
              "product_data" : [ {
                "product_name" : "cups",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.22",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00000.html",
          "name" : "SUSE-SA:2008:012",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29087",
          "name" : "29087",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29189",
          "name" : "29189",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29251",
          "name" : "29251",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2008-084.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2008-084.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2008-098.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2008-098.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0091",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0091",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0091",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0091",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:050",
          "name" : "MDVSA-2008:050",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0153.html",
          "name" : "RHSA-2008:0153",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0161.html",
          "name" : "RHSA-2008:0161",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488966/100/0/threaded",
          "name" : "20080229 rPSA-2008-0091-1 cups",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27988",
          "name" : "27988",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019497",
          "name" : "1019497",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40845",
          "name" : "cups-ippbrowse-useafterfree-dos(40845)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2283",
          "name" : "https://issues.rpath.com/browse/RPL-2283",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9492",
          "name" : "oval:org.mitre.oval:def:9492",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Use-after-free vulnerability in CUPS before 1.1.22, and possibly other versions, allows remote attackers to cause a denial of service (crash) via crafted IPP packets."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:desktop:3.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:desktop:4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:as_3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:as_4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:es_3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:es_4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:ws_3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:ws_4:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:easy_software_products:cups:1.1.17:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:easy_software_products:cups:1.1.22:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-26T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0598",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00000.html",
          "name" : "SUSE-SA:2008:047",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00001.html",
          "name" : "SUSE-SA:2008:048",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00003.html",
          "name" : "SUSE-SA:2008:049",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2008-0508.html",
          "name" : "RHSA-2008:0508",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30849",
          "name" : "30849",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30850",
          "name" : "30850",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31107",
          "name" : "31107",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31551",
          "name" : "31551",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32103",
          "name" : "32103",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32104",
          "name" : "32104",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/33201",
          "name" : "33201",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/33586",
          "name" : "33586",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1630",
          "name" : "DSA-1630",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:220",
          "name" : "MDVSA-2008:220",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0519.html",
          "name" : "RHSA-2008:0519",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0973.html",
          "name" : "RHSA-2008:0973",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2009-0009.html",
          "name" : "RHSA-2009:0009",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29942",
          "name" : "29942",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020367",
          "name" : "1020367",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-625-1",
          "name" : "USN-625-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=433938",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=433938",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/43554",
          "name" : "linux-kernel-emulation-disclosure(43554)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10721",
          "name" : "oval:org.mitre.oval:def:10721",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6201",
          "name" : "oval:org.mitre.oval:def:6201",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the 32-bit and 64-bit emulation in the Linux kernel 2.6.9, 2.6.18, and probably other versions allows local users to read uninitialized memory via unknown vectors involving a crafted binary."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-06-30T22:41Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0599",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://cvs.php.net/viewvc.cgi/php-src/sapi/cgi/cgi_main.c?r1=1.267.2.15.2.50.2.12&r2=1.267.2.15.2.50.2.13&diff_format=u",
          "name" : "http://cvs.php.net/viewvc.cgi/php-src/sapi/cgi/cgi_main.c?r1=1.267.2.15.2.50.2.12&r2=1.267.2.15.2.50.2.13&diff_format=u",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01476437",
          "name" : "HPSBUX02342",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html",
          "name" : "APPLE-SA-2008-07-31",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=124654546101607&w=2",
          "name" : "SSRT090085",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=125631037611762&w=2",
          "name" : "HPSBUX02465",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30048",
          "name" : "30048",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30083",
          "name" : "30083",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30345",
          "name" : "30345",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30616",
          "name" : "30616",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30757",
          "name" : "30757",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30828",
          "name" : "30828",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31200",
          "name" : "31200",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31326",
          "name" : "31326",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32746",
          "name" : "32746",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/35650",
          "name" : "35650",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200811-05.xml",
          "name" : "GLSA-200811-05",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0176",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0176",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/147027",
          "name" : "VU#147027",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:127",
          "name" : "MDVSA-2008:127",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:128",
          "name" : "MDVSA-2008:128",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2008/05/02/2",
          "name" : "[oss-security] 20080502 CVE Request (PHP)",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/ChangeLog-5.php",
          "name" : "http://www.php.net/ChangeLog-5.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0505.html",
          "name" : "RHSA-2008:0505",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/492535/100/0/threaded",
          "name" : "20080523 rPSA-2008-0176-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29009",
          "name" : "29009",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019958",
          "name" : "1019958",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.488951",
          "name" : "SSA:2008-128-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-628-1",
          "name" : "USN-628-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1412",
          "name" : "ADV-2008-1412",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1810/references",
          "name" : "ADV-2008-1810",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2268",
          "name" : "ADV-2008-2268",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42137",
          "name" : "php-vector-unspecified(42137)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2503",
          "name" : "https://issues.rpath.com/browse/RPL-2503",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5510",
          "name" : "oval:org.mitre.oval:def:5510",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00773.html",
          "name" : "FEDORA-2008-3864",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00779.html",
          "name" : "FEDORA-2008-3606",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:beta4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.2.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-05-05T17:20Z",
    "lastModifiedDate" : "2018-10-15T22:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0600",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.22.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.23.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.24.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00005.html",
          "name" : "SUSE-SA:2008:007",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00002.html",
          "name" : "SUSE-SA:2008:013",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.html",
          "name" : "SUSE-SA:2008:030",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=linux-kernel&m=120263652322197&w=2",
          "name" : "[linux-kernel] 20080210 Re: [PATCH] kernel 2.6.24.1 still vulnerable to the vmsplice local root exploit",
          "refsource" : "MLIST",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://marc.info/?l=linux-kernel&m=120264520431307&w=2",
          "name" : "[linux-kernel] 20080210 Re: [PATCH] kernel 2.6.24.1 still vulnerable to the vmsplice local root exploit",
          "refsource" : "MLIST",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://marc.info/?l=linux-kernel&m=120264773202422&w=2",
          "name" : "[linux-kernel] 20080210 Re: [PATCH] kernel 2.6.24.1 still vulnerable to the vmsplice local root exploit",
          "refsource" : "MLIST",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://marc.info/?l=linux-kernel&m=120266328220808&w=2",
          "name" : "[linux-kernel] 20080210 Re: [PATCH] kernel 2.6.24.1 still vulnerable to the vmsplice local root exploit",
          "refsource" : "MLIST",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://marc.info/?l=linux-kernel&m=120266353621139&w=2",
          "name" : "[linux-kernel] 20080210 Re: [PATCH] kernel 2.6.24.1 still vulnerable to the vmsplice local root exploit",
          "refsource" : "MLIST",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28835",
          "name" : "28835",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28858",
          "name" : "28858",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28875",
          "name" : "28875",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28889",
          "name" : "28889",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28896",
          "name" : "28896",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28912",
          "name" : "28912",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28925",
          "name" : "28925",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28933",
          "name" : "28933",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28937",
          "name" : "28937",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29245",
          "name" : "29245",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30818",
          "name" : "30818",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019393",
          "name" : "1019393",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0052",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0052",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0052",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0052",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1494",
          "name" : "DSA-1494",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:043",
          "name" : "MDVSA-2008:043",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:044",
          "name" : "MDVSA-2008:044",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0129.html",
          "name" : "RHSA-2008:0129",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488009/100/0/threaded",
          "name" : "20080212 rPSA-2008-0052-1 kernel",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27704",
          "name" : "27704",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27801",
          "name" : "27801",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-577-1",
          "name" : "USN-577-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0487/references",
          "name" : "ADV-2008-0487",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=432229",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=432229",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=432517",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=432517",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2237",
          "name" : "https://issues.rpath.com/browse/RPL-2237",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11358",
          "name" : "oval:org.mitre.oval:def:11358",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5092",
          "name" : "5092",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00254.html",
          "name" : "FEDORA-2008-1422",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00255.html",
          "name" : "FEDORA-2008-1423",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00270.html",
          "name" : "FEDORA-2008-1433",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00485.html",
          "name" : "FEDORA-2008-1629",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows local users to gain root privileges via crafted arguments in a vmsplice system call, a different vulnerability than CVE-2008-0009 and CVE-2008-0010."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:git1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:git2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:git3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:git4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:git5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:git6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:git7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.22.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.23.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.24:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.24:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.24.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T21:00Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0601",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "all_club_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "all_club_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.0.1f",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27624",
          "name" : "27624",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5064",
          "name" : "5064",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:all_club_cms:all_club_cms:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.0.1f"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0602",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "all_club_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "all_club_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.0.1f",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://www.exploit-db.com/exploits/5061",
          "name" : "5061",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the class_name parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:all_club_cms:all_club_cms:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.0.1f"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0603",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "amazoop",
            "product" : {
              "product_data" : [ {
                "product_name" : "awesom",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_awesom",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_awesom",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27607",
          "name" : "27607",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5058",
          "name" : "5058",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the amazOOP Awesom! (com_awesom) 0.3.2component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter in a viewlist task."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:amazoop:awesom:0.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_awesom:0.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_awesom:0.3.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0604",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xlight_ftp_server",
            "product" : {
              "product_data" : [ {
                "product_name" : "xlight_ftp_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.82",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-255"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28755",
          "name" : "28755",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27602",
          "name" : "27602",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.xlightftpd.com/whatsnew.htm",
          "name" : "http://www.xlightftpd.com/whatsnew.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The LDAP authentication feature in XLight FTP Server before 2.83, when used with some unspecified LDAP servers, does not check for blank passwords, which allows remote attackers to bypass intended access restrictions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xlight_ftp_server:xlight_ftp_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.82"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0605",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "astrosoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "astrosoft_helpdesk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.95.227",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3612",
          "name" : "3612",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487487/100/0/threaded",
          "name" : "20080204 [DSECRG-08-011] Astrosoft HelpDesk Multiple XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488107/100/0/threaded",
          "name" : "20080214 [DSECRG-08-011 | FIX INFORMATION] Astrosoft HelpDesk Multiple XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27610",
          "name" : "27610",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp.  NOTE: for vector 2, the XSS occurs in a forced SQL error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:astrosoft:astrosoft_helpdesk:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.95.227"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0606",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_shambo2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_shambo2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "phil_taylor",
            "product" : {
              "product_data" : [ {
                "product_name" : "shambo2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27609",
          "name" : "27609",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40238",
          "name" : "shambo2-index-sql-injection(40238)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5059",
          "name" : "5059",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Shambo2 (com_shambo2) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_shambo2:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_shambo2:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phil_taylor:shambo2:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0607",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_sobi2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_sobi2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "sigsiu.net",
            "product" : {
              "product_data" : [ {
                "product_name" : "sobi2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27617",
          "name" : "27617",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5038",
          "name" : "5038",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) 2.5.3 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_sobi2:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_sobi2:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sigsiu.net:sobi2:2.5.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0608",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ipswitch",
            "product" : {
              "product_data" : [ {
                "product_name" : "ws_ftp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/ftplogsrvz-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/ftplogsrvz-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28761",
          "name" : "28761",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487506/100/0/threaded",
          "name" : "20080204 Socket termination in FTP Log Server 7.9.14.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27612",
          "name" : "27612",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0408",
          "name" : "ADV-2008-0408",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Logging Server (ftplogsrv.exe) 7.9.14.0 and earlier in IPSwitch WS_FTP 6.1 allows remote attackers to cause a denial of service (loss of responsiveness) via a large number of large packets to port 5151/udp, which causes the listening socket to terminate and prevents log commands from being recorded, a different vulnerability than CVE-2007-3823."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ipswitch:ws_ftp:6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0609",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "divideconcept",
            "product" : {
              "product_data" : [ {
                "product_name" : "vhd_web_pack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28712",
          "name" : "28712",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3613",
          "name" : "3613",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487485/100/0/threaded",
          "name" : "20080204 [DSECRG-08-010] VHD Web Pack 2.0 Local File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27621",
          "name" : "27621",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5060",
          "name" : "5060",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in index.php in DivideConcept VHD Web Pack 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:divideconcept:vhd_web_pack:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0610",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ultravnc",
            "product" : {
              "product_data" : [ {
                "product_name" : "ultravnc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4_rc6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4_rc7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4_rc8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forum.ultravnc.info/viewtopic.php?t=11850",
          "name" : "http://forum.ultravnc.info/viewtopic.php?t=11850",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28747",
          "name" : "28747",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=571174&group_id=63887",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=571174&group_id=63887",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://ultravnc.svn.sourceforge.net/viewvc/ultravnc/UltraVNC%20Project%20Root/UltraVNC/vncviewer/ClientConnection.cpp?sortby=date&r1=169&r2=168&pathrev=169",
          "name" : "http://ultravnc.svn.sourceforge.net/viewvc/ultravnc/UltraVNC%20Project%20Root/UltraVNC/vncviewer/ClientConnection.cpp?sortby=date&r1=169&r2=168&pathrev=169",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.exploit-db.com/exploits/18666",
          "name" : "18666",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/721460",
          "name" : "VU#721460",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27561",
          "name" : "27561",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019293",
          "name" : "1019293",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0392",
          "name" : "ADV-2008-0392",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the ClientConnection::NegotiateProtocolVersion function in vncviewer/ClientConnection.cpp in vncviewer for UltraVNC 1.0.2 and 1.0.4 before 01252008, when in LISTENING mode or when using the DSM plugin, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a modified size value."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ultravnc:ultravnc:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ultravnc:ultravnc:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ultravnc:ultravnc:1.0.4_rc6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ultravnc:ultravnc:1.0.4_rc7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ultravnc:ultravnc:1.0.4_rc8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2012-08-14T02:37Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0611",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rmsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "gallery_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "xoops",
            "product" : {
              "product_data" : [ {
                "product_name" : "xoops",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27623",
          "name" : "27623",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5062",
          "name" : "5062",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in rmgs/images.php in the RMSOFT Gallery System 2.0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rmsoft:gallery_system:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xoops:xoops:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0612",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xoops",
            "product" : {
              "product_data" : [ {
                "product_name" : "xoops",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.18",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3614",
          "name" : "3614",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487484/100/0/threaded",
          "name" : "20080204 [DSECRG-08-009] xoops 2.0.18 Local File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27622",
          "name" : "27622",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://xoops.svn.sourceforge.net/viewvc/xoops/XoopsCore/branches/2.0.x/2.0.18.1/docs/changelog.txt?r1=1283&r2=1282&pathrev=1283",
          "name" : "http://xoops.svn.sourceforge.net/viewvc/xoops/XoopsCore/branches/2.0.x/2.0.18.1/docs/changelog.txt?r1=1283&r2=1282&pathrev=1283",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://xoops.svn.sourceforge.net/viewvc/xoops?view=rev&revision=1283",
          "name" : "http://xoops.svn.sourceforge.net/viewvc/xoops?view=rev&revision=1283",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5057",
          "name" : "5057",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xoops:xoops:2.0.18:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0613",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xoops",
            "product" : {
              "product_data" : [ {
                "product_name" : "xoops",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.18",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-59"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3614",
          "name" : "3614",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/tracker/index.php?func=detail&atid=430840&aid=1881236&group_id=41586",
          "name" : "http://sourceforge.net/tracker/index.php?func=detail&atid=430840&aid=1881236&group_id=41586",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487484/100/0/threaded",
          "name" : "20080204 [DSECRG-08-009] xoops 2.0.18 Local File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://xoops.svn.sourceforge.net/viewvc/xoops?view=rev&revision=1282",
          "name" : "http://xoops.svn.sourceforge.net/viewvc/xoops?view=rev&revision=1282",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5057",
          "name" : "5057",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Open redirect vulnerability in htdocs/user.php in XOOPS 2.0.18 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the xoops_redirect parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xoops:xoops:2.0.18:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0614",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "photokorn",
            "product" : {
              "product_data" : [ {
                "product_name" : "gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.543",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27627",
          "name" : "27627",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5065",
          "name" : "5065",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in Photokorn Gallery 1.543 allows remote attackers to execute arbitrary SQL commands via the pic parameter in a showpic action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:photokorn:gallery:1.543:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0615",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dmsguestbook",
            "product" : {
              "product_data" : [ {
                "product_name" : "dmsguestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28759",
          "name" : "28759",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3615",
          "name" : "3615",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487437/100/0/threaded",
          "name" : "20080202 Wordpress Plugin dmsguestbook 1.7.0 Multiple Remote Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27575",
          "name" : "27575",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5035",
          "name" : "5035",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in wp-admin/admin.php in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) folder and (2) file parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dmsguestbook:dmsguestbook:1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dmsguestbook:dmsguestbook:1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0616",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dmsguestbook",
            "product" : {
              "product_data" : [ {
                "product_name" : "dmsguestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3615",
          "name" : "3615",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487437/100/0/threaded",
          "name" : "20080202 Wordpress Plugin dmsguestbook 1.7.0 Multiple Remote Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40196",
          "name" : "dmsguestbook-unspecified-sql-injection(40196)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5035",
          "name" : "5035",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors.  NOTE: it is not clear whether this issue crosses privilege boundaries."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dmsguestbook:dmsguestbook:1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0617",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "daniel_m._schurter",
            "product" : {
              "product_data" : [ {
                "product_name" : "dmsguestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3615",
          "name" : "3615",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487437/100/0/threaded",
          "name" : "20080202 Wordpress Plugin dmsguestbook 1.7.0 Multiple Remote Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27575",
          "name" : "27575",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5035",
          "name" : "5035",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter to wp-admin/admin.php, or the (2) messagefield parameter in the guestbook page, and the (3) title parameter in the messagearea."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:daniel_m._schurter:dmsguestbook:1.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0618",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "daniel_m._schurter",
            "product" : {
              "product_data" : [ {
                "product_name" : "dmsguestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28759",
          "name" : "28759",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) gbname, (2) gbemail, (3) gburl, and (4) gbmsg parameters to unspecified programs.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:daniel_m._schurter:dmsguestbook:1.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:daniel_m._schurter:dmsguestbook:1.8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0619",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nero",
            "product" : {
              "product_data" : [ {
                "product_name" : "mediaplayer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.0.35",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28765",
          "name" : "28765",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3616",
          "name" : "3616",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487578/100/0/threaded",
          "name" : "20080205 NERO Media Player <= 1.4.0.35b Remote Buffer Overflow( .M3U)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27615",
          "name" : "27615",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0405",
          "name" : "ADV-2008-0405",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5063",
          "name" : "5063",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in NeroMediaPlayer.exe in Nero Media Player 1.4.0.35 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (persistent crash) via a long URI in a .M3U file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nero:mediaplayer:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4.0.35"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0620",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sap",
            "product" : {
              "product_data" : [ {
                "product_name" : "sapgui",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "saplpd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.28",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "sapsprint",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28786",
          "name" : "28786",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28811",
          "name" : "28811",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3619",
          "name" : "3619",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487508/100/0/threaded",
          "name" : "20080204 Multiple vulnerabilities in SAPlpd 6.28",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487575/100/0/threaded",
          "name" : "20080205 Re: Multiple vulnerabilities in SAPlpd 6.28",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27613",
          "name" : "27613",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019300",
          "name" : "1019300",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0409",
          "name" : "ADV-2008-0409",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0438",
          "name" : "ADV-2008-0438",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to cause a denial of service (crash) via a 0x53 LPD command, which causes the server to terminate."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sap:sapgui:7.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sap:saplpd:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.28"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sap:sapsprint:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0621",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sap",
            "product" : {
              "product_data" : [ {
                "product_name" : "sapgui",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "saplpd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.28",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "sapsprint",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28786",
          "name" : "28786",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28811",
          "name" : "28811",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3619",
          "name" : "3619",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487508/100/0/threaded",
          "name" : "20080204 Multiple vulnerabilities in SAPlpd 6.28",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487575/100/0/threaded",
          "name" : "20080205 Re: Multiple vulnerabilities in SAPlpd 6.28",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27613",
          "name" : "27613",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019300",
          "name" : "1019300",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0409",
          "name" : "ADV-2008-0409",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0438",
          "name" : "ADV-2008-0438",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5079",
          "name" : "5079",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary code via long arguments to the (1) 0x01, (2) 0x02, (3) 0x03, (4) 0x04, and (5) 0x05 LPD commands."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sap:sapgui:7.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sap:saplpd:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.28"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sap:sapsprint:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0622",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "raidenhttpd",
            "product" : {
              "product_data" : [ {
                "product_name" : "raidenhttpd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.19",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jvn.jp/jp/JVN%2391868305/index.html",
          "name" : "JVN#91868305",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28770",
          "name" : "28770",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.raidenhttpd.com/jp/security.html",
          "name" : "http://www.raidenhttpd.com/jp/security.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27628",
          "name" : "27628",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0411",
          "name" : "ADV-2008-0411",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in RaidenHTTPD 2.0.19 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the ulang parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:raidenhttpd:raidenhttpd:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.19"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-06T12:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0623",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "yahoo",
            "product" : {
              "product_data" : [ {
                "product_name" : "music_jukebox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2.2.056",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28757",
          "name" : "28757",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/101676",
          "name" : "VU#101676",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27590",
          "name" : "27590",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019301",
          "name" : "1019301",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0396/references",
          "name" : "ADV-2008-0396",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5043",
          "name" : "5043",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5046",
          "name" : "5046",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5048",
          "name" : "5048",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows remote attackers to execute arbitrary code via a long argument to the AddImage method."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:music_jukebox:2.2.2.056:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-06T21:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0624",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "yahoo",
            "product" : {
              "product_data" : [ {
                "product_name" : "music_jukebox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2.2.56",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28757",
          "name" : "28757",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/101676",
          "name" : "VU#101676",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27579",
          "name" : "27579",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0396/references",
          "name" : "ADV-2008-0396",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5051",
          "name" : "5051",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddButton method, a different vulnerability than CVE-2008-0623."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:music_jukebox:2.2.2.56:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-06T21:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0625",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "yahoo",
            "product" : {
              "product_data" : [ {
                "product_name" : "music_jukebox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2.2.56",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28757",
          "name" : "28757",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/340860",
          "name" : "VU#340860",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27578",
          "name" : "27578",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019298",
          "name" : "1019298",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0396/references",
          "name" : "ADV-2008-0396",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5052",
          "name" : "5052",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddBitmap method."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:music_jukebox:2.2.2.56:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-06T21:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0626",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-6303.  Reason: This candidate is a duplicate of CVE-2007-6303.  Notes: All CVE users should reference CVE-2007-6303 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2008-02-06T21:00Z",
    "lastModifiedDate" : "2008-02-07T05:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0627",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-6304.  Reason: This candidate is a duplicate of CVE-2007-6304.  Notes: All CVE users should reference CVE-2007-6304 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2008-02-06T21:00Z",
    "lastModifiedDate" : "2008-02-07T05:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0628",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/277",
          "name" : "BEA08-201.00",
          "refsource" : "BEA",
          "tags" : [ ]
        }, {
          "url" : "http://scary.beasts.org/security/CESA-2007-002.html",
          "name" : "http://scary.beasts.org/security/CESA-2007-002.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28746",
          "name" : "28746",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29841",
          "name" : "29841",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29858",
          "name" : "29858",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30780",
          "name" : "30780",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200804-28.xml",
          "name" : "GLSA-200804-28",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3621",
          "name" : "3621",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-66-231246-1",
          "name" : "231246",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200804-20.xml",
          "name" : "GLSA-200804-20",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200806-11.xml",
          "name" : "GLSA-200806-11",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0245.html",
          "name" : "RHSA-2008:0245",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487434/100/0/threaded",
          "name" : "20080202 Sun JRE / JDK bug introduces XXE possibilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27553",
          "name" : "27553",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019292",
          "name" : "1019292",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0371",
          "name" : "ADV-2008-0371",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1252",
          "name" : "ADV-2008-1252",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9847",
          "name" : "oval:org.mitre.oval:def:9847",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the \"external general entities\" property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:update3:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 7.8,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-06T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0629",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mplayer",
            "product" : {
              "product_data" : [ {
                "product_name" : "mplayer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.02rc2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28955",
          "name" : "28955",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28956",
          "name" : "28956",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29307",
          "name" : "29307",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-16.xml",
          "name" : "GLSA-200803-16",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1496",
          "name" : "DSA-1496",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:045",
          "name" : "MDVSA-2008:045",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mplayerhq.hu/design7/news.html",
          "name" : "http://www.mplayerhq.hu/design7/news.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27765",
          "name" : "27765",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in stream_cddb.c in MPlayer 1.0rc2 and SVN before r25824 allows remote user-assisted attackers to execute arbitrary code via a CDDB database entry containing a long album title."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mplayer:mplayer:1.02rc2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-06T21:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0630",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mplayer",
            "product" : {
              "product_data" : [ {
                "product_name" : "mplayer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.02rc2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28955",
          "name" : "28955",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28956",
          "name" : "28956",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29307",
          "name" : "29307",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-16.xml",
          "name" : "GLSA-200803-16",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1496",
          "name" : "DSA-1496",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:045",
          "name" : "MDVSA-2008:045",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mplayerhq.hu/design7/news.html",
          "name" : "http://www.mplayerhq.hu/design7/news.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27766",
          "name" : "27766",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in url.c in MPlayer 1.0rc2 and SVN before r25823 allows remote attackers to execute arbitrary code via a crafted URL that prevents the IPv6 parsing code from setting a pointer to NULL, which causes the buffer to be reused by the unescape code."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mplayer:mplayer:1.02rc2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-06T21:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0631",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "afterlogic",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailbee_objects",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27481",
          "name" : "27481",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40011",
          "name" : "mailbee-mailbee-file-overwrite(40011)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4999",
          "name" : "4999",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple ActiveX controls in MailBee.dll in MailBee Objects 5.5 allow remote attackers to (1) overwrite arbitrary files via the SaveToDisk method, or (2) modify files via the AddStringToFile method."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:afterlogic:mailbee_objects:5.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-06T21:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0632",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lightblog",
            "product" : {
              "product_data" : [ {
                "product_name" : "lightblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://omni.netsons.org/blog/?p=11",
          "name" : "http://omni.netsons.org/blog/?p=11",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28734",
          "name" : "28734",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3617",
          "name" : "3617",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487398/100/0/threaded",
          "name" : "20080201 LightBlog Remote File Upload Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27562",
          "name" : "27562",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5033",
          "name" : "5033",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unrestricted file upload vulnerability in cp_upload_image.php in LightBlog 9.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the blog's root directory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lightblog:lightblog:9.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0633",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "anon_proxy_server",
            "product" : {
              "product_data" : [ {
                "product_name" : "anon_proxy_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.102",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3618",
          "name" : "3618",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487446/100/0/threaded",
          "name" : "20080203 Anon Proxy Server <= 0.102 remote buffer overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27593",
          "name" : "27593",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://sourceforge.net/project/shownotes.php?group_id=138780&release_id=571924",
          "name" : "https://sourceforge.net/project/shownotes.php?group_id=138780&release_id=571924",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Anon Proxy Server 0.102 and earlier, when user authentication is enabled, allows remote attackers to cause a denial of service (exception) via a user name with a large number of quotes, which triggers the overflow during escaping."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:anon_proxy_server:anon_proxy_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.102"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0634",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sejoong_namo",
            "product" : {
              "product_data" : [ {
                "product_name" : "activesquare",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "namoinstall.1_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28649",
          "name" : "28649",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40199",
          "name" : "namo-activesquare-bo(40199)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5045",
          "name" : "5045",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote attackers to execute arbitrary code via a long argument to the Install method, a different vulnerability than CVE-2008-0551."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sejoong_namo:activesquare:6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sejoong_namo:namoinstall.1_activex_control:3.0.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T21:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0635",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openads",
            "product" : {
              "product_data" : [ {
                "product_name" : "openads",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28790",
          "name" : "28790",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3620",
          "name" : "3620",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487486/100/0/threaded",
          "name" : "20080204 [OPENADS-SA-2008-001] Openads 2.4.2 vulnerability fixed",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27603",
          "name" : "27603",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the delivery engine in Openads 2.4.0 through 2.4.2 allows remote attackers to execute arbitrary PHP code via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openads:openads:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openads:openads:2.4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-06T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0636",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "level_platforms",
            "product" : {
              "product_data" : [ {
                "product_name" : "managed_workplace_service_center",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3659",
          "name" : "3659",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487811/100/0/threaded",
          "name" : "20080208 SECURITY ADVISORY - Level Platforms, Inc. Service Center Install Data HTTP Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488201/100/0/threaded",
          "name" : "20080214 Re: SECURITY ADVISORY - Level Platforms, Inc. Service Center Install Data HTTP Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/496074/100/0/threaded",
          "name" : "20080908 Re: Re: SECURITY ADVISORY - Level Platforms, Inc. Service Center Install Data HTTP Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27702",
          "name" : "27702",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Level Platforms, Inc. (LPI) Managed Workplace Service Center 4.x, 5.x and 6.x allows remote attackers to obtain sensitive information via a direct request to About/SC_About.htm, which provides version and patch information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:level_platforms:managed_workplace_service_center:4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:level_platforms:managed_workplace_service_center:5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:level_platforms:managed_workplace_service_center:6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0638",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "veritas_storage_foundation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29050",
          "name" : "29050",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019459",
          "name" : "1019459",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488420/100/0/threaded",
          "name" : "20080220 ZDI-08-007: Symantec VERITAS Storage Foundation Administrator Service Heap Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/25778",
          "name" : "25778",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.symantec.com/avcenter/security/Content/2008.02.20a.html",
          "name" : "http://www.symantec.com/avcenter/security/Content/2008.02.20a.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-007.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-007.html",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the Veritas Enterprise Administrator (VEA) service (aka vxsvc.exe) in Symantec Veritas Storage Foundation 5.0 allows remote attackers to execute arbitrary code via a packet with a crafted value of a certain size field, which is not checked for consistency with the actual buffer size."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:veritas_storage_foundation:5.0:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:veritas_storage_foundation:5.0:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:veritas_storage_foundation:5.0:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:veritas_storage_foundation:5.0:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:veritas_storage_foundation:5.0:*:windows_2000:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:veritas_storage_foundation:5.0:32bit:windows_2003:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:veritas_storage_foundation:5.0:64bit:windows_2003:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-21T20:44Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0639",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "novell",
            "product" : {
              "product_data" : [ {
                "product_name" : "client",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.91",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://download.novell.com/Download?buildid=SszG22IIugM~",
          "name" : "http://download.novell.com/Download?buildid=SszG22IIugM~",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://marc.info/?l=full-disclosure&m=120276962211348&w=2",
          "name" : "20080211 ZDI-08-005: Novell Client NWSPOOL.DLL EnumPrinters Stack Overflow Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28895",
          "name" : "28895",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5008300.html",
          "name" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5008300.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487980/100/0/threaded",
          "name" : "20080211 ZDI-08-005: Novell Client NWSPOOL.DLL EnumPrinters Stack Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27741",
          "name" : "27741",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019366",
          "name" : "1019366",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0496",
          "name" : "ADV-2008-0496",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-005.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-005.html",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the EnumPrinters function in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2, SP3, and SP4 for Windows allows remote attackers to execute arbitrary code via a crafted RPC request, aka Novell bug 353138, a different vulnerability than CVE-2006-5854.  NOTE: this issue exists because of an incomplete fix for CVE-2007-6701."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:novell:client:4.91:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:novell:client:4.91:sp3:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:novell:client:4.91:sp4:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0640",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "ghost_solutions_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28853",
          "name" : "28853",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27644",
          "name" : "27644",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019356",
          "name" : "1019356",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.symantec.com/avcenter/security/Content/2008.02.07.html",
          "name" : "http://www.symantec.com/avcenter/security/Content/2008.02.07.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0474",
          "name" : "ADV-2008-0474",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:ghost_solutions_suite:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:ghost_solutions_suite:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:ghost_solutions_suite:2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-08T02:00Z",
    "lastModifiedDate" : "2011-07-25T04:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0642",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "robohelp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28945",
          "name" : "28945",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019397",
          "name" : "1019397",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.adobe.com/support/security/bulletins/apsb08-05.html",
          "name" : "http://www.adobe.com/support/security/bulletins/apsb08-05.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27763",
          "name" : "27763",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0537",
          "name" : "ADV-2008-0537",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in files created by Adobe RoboHelp 6 and 7, possibly involving use of a (1) WebHelp5 (WebHelp5Ext) or (2) WildFire (WildFireExt) extension, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-1280."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:robohelp:6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:robohelp:7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-15T01:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0643",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "coldfusion",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29332",
          "name" : "29332",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.adobe.com/support/security/bulletins/apsb08-06.html",
          "name" : "http://www.adobe.com/support/security/bulletins/apsb08-06.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28205",
          "name" : "28205",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019589",
          "name" : "1019589",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0862/references",
          "name" : "ADV-2008-0862",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41144",
          "name" : "adobe-coldfusion-useragent-xss(41144)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:coldfusion:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:coldfusion:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:coldfusion:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:coldfusion:8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-12T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0644",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "coldfusion",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29332",
          "name" : "29332",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.adobe.com/support/security/bulletins/apsb08-07.html",
          "name" : "http://www.adobe.com/support/security/bulletins/apsb08-07.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28205",
          "name" : "28205",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019590",
          "name" : "1019590",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0862/references",
          "name" : "ADV-2008-0862",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41145",
          "name" : "coldfusion-setencoding-xss(41145)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism for applications via unspecified vectors related to the setEncoding function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:coldfusion:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:coldfusion:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:coldfusion:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:coldfusion:8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-12T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0645",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "portail_web_php",
            "product" : {
              "product_data" : [ {
                "product_name" : "portail_web_php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27616",
          "name" : "27616",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 allow remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) config/conf-activation.php, (2) menu/item.php, and (3) modules/conf_modules.php in admin/system/; and (4) system/login.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:portail_web_php:portail_web_php:2.5.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T21:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0646",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "deluge_team",
            "product" : {
              "product_data" : [ {
                "product_name" : "deluge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.8.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "rasterbar_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "libtorrent",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.12",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://deluge-torrent.org/Changelog.php",
          "name" : "http://deluge-torrent.org/Changelog.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_12/include/libtorrent/bencode.hpp?r1=956&r2=1968&pathrev=1968",
          "name" : "http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_12/include/libtorrent/bencode.hpp?r1=956&r2=1968&pathrev=1968",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_12/include/libtorrent/bencode.hpp?view=log&pathrev=1968#rev1968",
          "name" : "http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_12/include/libtorrent/bencode.hpp?view=log&pathrev=1968#rev1968",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_13/include/libtorrent/bencode.hpp?view=log&pathrev=1968",
          "name" : "http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_13/include/libtorrent/bencode.hpp?view=log&pathrev=1968",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/trunk/include/libtorrent/bencode.hpp?view=log&pathrev=1968",
          "name" : "http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/trunk/include/libtorrent/bencode.hpp?view=log&pathrev=1968",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28699",
          "name" : "28699",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28700",
          "name" : "28700",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28781",
          "name" : "28781",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28782",
          "name" : "28782",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27597",
          "name" : "27597",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0383",
          "name" : "ADV-2008-0383",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0384",
          "name" : "ADV-2008-0384",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00001.html",
          "name" : "FEDORA-2008-1198",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The bdecode_recursive function in include/libtorrent/bencode.hpp in Rasterbar Software libtorrent before 0.12.1, as used in Deluge before 0.5.8.3 and other products, allows context-dependent attackers to cause a denial of service (stack exhaustion and crash) via a crafted bencoded message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:deluge_team:deluge:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.5.8.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rasterbar_software:libtorrent:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.12"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T21:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0647",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ourgame.com",
            "product" : {
              "product_data" : [ {
                "product_name" : "glworld",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.1.29",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "hangameplugincn18_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28809",
          "name" : "28809",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27626",
          "name" : "27626",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.symantec.com/enterprise/security_response/weblog/2008/02/zeroday_exploit_for_lianzong_g.html",
          "name" : "http://www.symantec.com/enterprise/security_response/weblog/2008/02/zeroday_exploit_for_lianzong_g.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0427",
          "name" : "ADV-2008-0427",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5153",
          "name" : "5153",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the (1) hgs_startGame and (2) hgs_startNotify methods, as exploited in the wild as of February 2008.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ourgame.com:glworld:2.6.1.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ourgame.com:hangameplugincn18_activex_control:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T21:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0648",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "opensiteadmin",
            "product" : {
              "product_data" : [ {
                "product_name" : "opensiteadmin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27640",
          "name" : "27640",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5068",
          "name" : "5068",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in OpenSiteAdmin 0.9.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) indexFooter.php; and (2) DatabaseManager.php, (3) FieldManager.php, (4) Filter.php, (5) Form.php, (6) FormManager.php, (7) LoginManager.php, and (8) Filters/SingleFilter.php in scripts/classes/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opensiteadmin:opensiteadmin:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.9.1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T21:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0649",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adp",
            "product" : {
              "product_data" : [ {
                "product_name" : "astanda_directory_project",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27646",
          "name" : "27646",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5071",
          "name" : "5071",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in detail.php in Astanda Directory Project (ADP) 1.2 and 1.3 allows remote attackers to execute arbitrary SQL commands via the link_id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adp:astanda_directory_project:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adp:astanda_directory_project:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T21:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0650",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "simple_os_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "simple_os_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1c_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27589",
          "name" : "27589",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in login.php in Simple OS CMS 0.1c beta allows remote attackers to execute arbitrary SQL commands via the username field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:simple_os_cms:simple_os_cms:0.1c_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T21:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0651",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pedro_santana_codice",
            "product" : {
              "product_data" : [ {
                "product_name" : "cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27592",
          "name" : "27592",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in login.php in Pedro Santana Codice CMS allows remote attackers to execute arbitrary SQL commands via the username field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pedro_santana_codice:cms:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T21:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0652",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_downloads",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_downloads",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27648",
          "name" : "27648",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5073",
          "name" : "5073",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_downloads:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_downloads:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T21:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0653",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_ynews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27649",
          "name" : "27649",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5072",
          "name" : "5072",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Ynews (com_ynews) 1.0.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showYNews action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_ynews:1.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T21:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0654",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "azucar_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "azucar_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3622",
          "name" : "3622",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487595/100/0/threaded",
          "name" : "20080205 [DSECRG-08-012] Multiple LFI in Azucar CMS 1.3",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in Azucar CMS 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _VIEW (view) parameter to (1) index.php, (2) html/sitio/index.php, or (3) src/sistema/vistas/template/tpl_inicio.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azucar_cms:azucar_cms:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0655",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "acrobat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.1",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "acrobat_reader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.adobe.com/acroread/2008/02/adobe_reader_812_for_linux_and.html",
          "name" : "http://blogs.adobe.com/acroread/2008/02/adobe_reader_812_for_linux_and.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://kb.adobe.com/selfservice/viewContent.do?externalId=kb403079&sliceId=1",
          "name" : "http://kb.adobe.com/selfservice/viewContent.do?externalId=kb403079&sliceId=1",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00007.html",
          "name" : "SUSE-SA:2008:009",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28802",
          "name" : "28802",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28851",
          "name" : "28851",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28983",
          "name" : "28983",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29065",
          "name" : "29065",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29205",
          "name" : "29205",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30840",
          "name" : "30840",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-01.xml",
          "name" : "GLSA-200803-01",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019346",
          "name" : "1019346",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-239286-1",
          "name" : "239286",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.adobe.com/support/security/advisories/apsa08-01.html",
          "name" : "http://www.adobe.com/support/security/advisories/apsa08-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.adobe.com/support/security/bulletins/apsb08-13.html",
          "name" : "http://www.adobe.com/support/security/bulletins/apsb08-13.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0144.html",
          "name" : "RHSA-2008:0144",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27641",
          "name" : "27641",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043A.html",
          "name" : "TA08-043A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0425",
          "name" : "ADV-2008-0425",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1966/references",
          "name" : "ADV-2008-1966",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10299",
          "name" : "oval:org.mitre.oval:def:10299",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:4.0.5a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:4.0.5c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:5.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:6.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:6.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.1.1"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:3.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:3.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:4.0.5a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:4.0.5c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:5.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:5.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-07T21:00Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0656",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "emc",
            "product" : {
              "product_data" : [ {
                "product_name" : "documentum_administrator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.5_sp2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3.0.313",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "documentum_webtop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.5_sp2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3.0.317",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28810",
          "name" : "28810",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3626",
          "name" : "3626",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_Documentum_dmclTrace_Arbitrary_file_overwrite.pdf",
          "name" : "http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_Documentum_dmclTrace_Arbitrary_file_overwrite.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487603/100/0/threaded",
          "name" : "20080205 CYBSEC Security Advisory: Arbitrary file overwrite in Documentum Administrator / Documentum Webtop",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27632",
          "name" : "27632",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019305",
          "name" : "1019305",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0439",
          "name" : "ADV-2008-0439",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unrestricted file upload vulnerability in dmclTrace.jsp in EMC Documentum Administrator 5.3.0.313 and Webtop 5.3.0.317 allows remote attackers to overwrite arbitrary files via the filename attribute."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:emc:documentum_administrator:4.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:emc:documentum_administrator:5.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:emc:documentum_administrator:5.2.5_sp2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:emc:documentum_administrator:5.3.0.313:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:emc:documentum_webtop:5.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:emc:documentum_webtop:5.2.5_sp2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:emc:documentum_webtop:5.3.0.317:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0657",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0_update13",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.6.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/277",
          "name" : "BEA08-201.00",
          "refsource" : "BEA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.html",
          "name" : "SUSE-SA:2008:025",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28795",
          "name" : "28795",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28888",
          "name" : "28888",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29214",
          "name" : "29214",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29498",
          "name" : "29498",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29841",
          "name" : "29841",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29858",
          "name" : "29858",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29897",
          "name" : "29897",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30676",
          "name" : "30676",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30780",
          "name" : "30780",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31497",
          "name" : "31497",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200804-28.xml",
          "name" : "GLSA-200804-28",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-231261-1",
          "name" : "231261",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200804-20.xml",
          "name" : "GLSA-200804-20",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200806-11.xml",
          "name" : "GLSA-200806-11",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0123.html",
          "name" : "RHSA-2008:0123",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0156.html",
          "name" : "RHSA-2008:0156",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0210.html",
          "name" : "RHSA-2008:0210",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27650",
          "name" : "27650",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019308",
          "name" : "1019308",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/security/advisories/VMSA-2008-0010.html",
          "name" : "http://www.vmware.com/security/advisories/VMSA-2008-0010.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0429",
          "name" : "ADV-2008-0429",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1252",
          "name" : "ADV-2008-1252",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1856/references",
          "name" : "ADV-2008-1856",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11505",
          "name" : "oval:org.mitre.oval:def:11505",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:update13:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:update1:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.0"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0_update13"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:update1:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-07T21:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0658",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openldap",
            "product" : {
              "product_data" : [ {
                "product_name" : "openldap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.39",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html",
          "name" : "APPLE-SA-2009-11-09-1",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00011.html",
          "name" : "SUSE-SR:2008:010",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28914",
          "name" : "28914",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28926",
          "name" : "28926",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28953",
          "name" : "28953",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29068",
          "name" : "29068",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29225",
          "name" : "29225",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29256",
          "name" : "29256",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29461",
          "name" : "29461",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29682",
          "name" : "29682",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29957",
          "name" : "29957",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-28.xml",
          "name" : "GLSA-200803-28",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT3937",
          "name" : "http://support.apple.com/kb/HT3937",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0059",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0059",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0059",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0059",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1541",
          "name" : "DSA-1541",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:058",
          "name" : "MDVSA-2008:058",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-bdb/modrdn.c.diff?r1=1.197&r2=1.198&f=h",
          "name" : "http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-bdb/modrdn.c.diff?r1=1.197&r2=1.198&f=h",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5358",
          "name" : "http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5358",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0110.html",
          "name" : "RHSA-2008:0110",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488242/100/200/threaded",
          "name" : "20080212 rPSA-2008-0059-1 openldap openldap-clients openldap-servers",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27778",
          "name" : "27778",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019481",
          "name" : "1019481",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-584-1",
          "name" : "USN-584-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0536/references",
          "name" : "ADV-2008-0536",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2009/3184",
          "name" : "ADV-2009-3184",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40479",
          "name" : "openldap-modrdn-dos(40479)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9470",
          "name" : "oval:org.mitre.oval:def:9470",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 allows remote authenticated users to cause a denial of service (daemon crash) via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related issue to CVE-2007-6698."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openldap:openldap:2.3.39:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0659",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aurigma",
            "product" : {
              "product_data" : [ {
                "product_name" : "image_uploader_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.70",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "myspace",
            "product" : {
              "product_data" : [ {
                "product_name" : "myspaceuploader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.aurigma.com/post/2008/01/Another-security-problem---oh%2c-not-again.aspx",
          "name" : "http://blogs.aurigma.com/post/2008/01/Another-security-problem---oh%2c-not-again.aspx",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2008/Jan/0593.html",
          "name" : "20080131 MySpace Uploader ActiveX Control Buffer Overflow",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28715",
          "name" : "28715",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28733",
          "name" : "28733",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9060483",
          "name" : "http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9060483",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/776931",
          "name" : "VU#776931",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27533",
          "name" : "27533",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0344/references",
          "name" : "ADV-2008-0344",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0345/references",
          "name" : "ADV-2008-0345",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40118",
          "name" : "myspace-myspaceuploader-bo(40118)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5025",
          "name" : "5025",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote attackers to execute arbitrary code via a long Action property."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aurigma:image_uploader_activex_control:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.5.70"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:myspace:myspaceuploader:1.0.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-08T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0660",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aurigma",
            "product" : {
              "product_data" : [ {
                "product_name" : "image_uploader_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.70.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.126.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.17.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "facebook",
            "product" : {
              "product_data" : [ {
                "product_name" : "facebook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "photouploader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.57.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://seclists.org/fulldisclosure/2008/Feb/0023.html",
          "name" : "20080203 FaceBook/Aurigma Image/PhotoUploader Buffer Overflow",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28707",
          "name" : "28707",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28713",
          "name" : "28713",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9060483",
          "name" : "http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9060483",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/776931",
          "name" : "VU#776931",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27576",
          "name" : "27576",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27577",
          "name" : "27577",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019297",
          "name" : "1019297",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0391/references",
          "name" : "ADV-2008-0391",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0394/references",
          "name" : "ADV-2008-0394",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5049",
          "name" : "5049",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aurigma:image_uploader_activex_control:4.5.70.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aurigma:image_uploader_activex_control:4.5.126.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aurigma:image_uploader_activex_control:4.6.17.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aurigma:image_uploader_activex_control:5.0.10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:facebook:facebook:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:facebook:photouploader:4.5.57.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-08T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0661",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "illustrate",
            "product" : {
              "product_data" : [ {
                "product_name" : "dbpoweramp_audio_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3623",
          "name" : "3623",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487605/100/0/threaded",
          "name" : "20080205 dBpowerAMP Audio Player Release 2 Remote Buffer Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27635",
          "name" : "27635",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27639",
          "name" : "27639",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5067",
          "name" : "5067",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5069",
          "name" : "5069",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file with a long URI. NOTE: this might be the same issue as CVE-2004-1569."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:illustrate:dbpoweramp_audio_player:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-08T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0662",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "checkpoint",
            "product" : {
              "product_data" : [ {
                "product_name" : "vpn-1_secureclient",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "ngai_r56",
                    "version_affected" : "="
                  }, {
                    "version_value" : "ngx_r60",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://digihax.com/",
          "name" : "http://digihax.com/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28820",
          "name" : "28820",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3627",
          "name" : "3627",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487735/100/0/threaded",
          "name" : "20080207 Checkpoint SecuRemote/Secure Client NGX Auto Local Logon Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27675",
          "name" : "27675",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019317",
          "name" : "1019317",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0475",
          "name" : "ADV-2008-0475",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://usercenter.checkpoint.com/usercenter/portal/user/anon/page/supportCenter.psml",
          "name" : "https://usercenter.checkpoint.com/usercenter/portal/user/anon/page/supportCenter.psml",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\\SecuRemote registry key, which has Everyone/Full Control permissions, which allows local users to gain privileges by reading and reusing the credentials."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:checkpoint:vpn-1_secureclient:ngai_r56:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:checkpoint:vpn-1_secureclient:ngx_r60:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-08T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0663",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "novell",
            "product" : {
              "product_data" : [ {
                "product_name" : "challenge_response_client",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7.5",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "novell_client_for_windows",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.91_sp4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28792",
          "name" : "28792",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27631",
          "name" : "27631",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019304",
          "name" : "1019304",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0423/references",
          "name" : "ADV-2008-0423",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://secure-support.novell.com/KanisaPlatform/Publishing/686/3726376_f.SAL_Public.html",
          "name" : "https://secure-support.novell.com/KanisaPlatform/Publishing/686/3726376_f.SAL_Public.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Novell Challenge Response Client (LCM) 2.7.5 and earlier, as used with Novell Client for Windows 4.91 SP4, allows users with physical access to a locked system to obtain contents of the clipboard by pasting the contents into the Challenge Question field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:challenge_response_client:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.7.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:novell_client_for_windows:4.91_sp4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-08T02:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0664",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.71",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.10_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.10_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2_revision5002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2_revision5003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28823",
          "name" : "28823",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28920",
          "name" : "28920",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30960",
          "name" : "30960",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://wordpress.org/development/2008/02/wordpress-233/",
          "name" : "http://wordpress.org/development/2008/02/wordpress-233/",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1601",
          "name" : "DSA-1601",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27669",
          "name" : "27669",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019316",
          "name" : "1019316",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.village-idiot.org/archives/2008/02/02/wordpress-232-exploit-confirmed/",
          "name" : "http://www.village-idiot.org/archives/2008/02/02/wordpress-232-exploit-confirmed/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0448",
          "name" : "ADV-2008-0448",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=431547",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=431547",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00349.html",
          "name" : "FEDORA-2008-1512",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00416.html",
          "name" : "FEDORA-2008-1559",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog users via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:0.71:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.10_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.10_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.1.3_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.1.3_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.2_revision5002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.2_revision5003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.3.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-08T02:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0665",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "website_meta_language",
            "product" : {
              "product_data" : [ {
                "product_name" : "website_meta_language",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-59"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463907",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463907",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28829",
          "name" : "28829",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28856",
          "name" : "28856",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29353",
          "name" : "29353",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-23.xml",
          "name" : "GLSA-200803-23",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1492",
          "name" : "DSA-1492",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:076",
          "name" : "MDVSA-2008:076",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27685",
          "name" : "27685",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "wml_backend/p1_ipp/ipp.src in Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on the ipp.$$.tmp temporary file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:website_meta_language:website_meta_language:2.0.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-11T21:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0666",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "website_meta_language",
            "product" : {
              "product_data" : [ {
                "product_name" : "website_meta_language",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-59"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463907",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463907",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28829",
          "name" : "28829",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28856",
          "name" : "28856",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29353",
          "name" : "29353",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-23.xml",
          "name" : "GLSA-200803-23",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1492",
          "name" : "DSA-1492",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:076",
          "name" : "MDVSA-2008:076",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27685",
          "name" : "27685",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on (1) the /tmp/pe.tmp.$$ temporary file used by wml_contrib/wmg.cgi and (2) temporary files used by wml_backend/p3_eperl/eperl_sys.c."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:website_meta_language:website_meta_language:2.0.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-11T21:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0667",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "acrobat_reader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kb.adobe.com/selfservice/viewContent.do?externalId=kb403079&sliceId=1",
          "name" : "http://kb.adobe.com/selfservice/viewContent.do?externalId=kb403079&sliceId=1",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00007.html",
          "name" : "SUSE-SA:2008:009",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28802",
          "name" : "28802",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28851",
          "name" : "28851",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28983",
          "name" : "28983",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29065",
          "name" : "29065",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29205",
          "name" : "29205",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30840",
          "name" : "30840",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-01.xml",
          "name" : "GLSA-200803-01",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3625",
          "name" : "3625",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-239286-1",
          "name" : "239286",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.adobe.com/support/security/advisories/apsa08-01.html",
          "name" : "http://www.adobe.com/support/security/advisories/apsa08-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.adobe.com/support/security/bulletins/apsb08-13.html",
          "name" : "http://www.adobe.com/support/security/bulletins/apsb08-13.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.fortiguardcenter.com/advisory/FGA-2008-04.html",
          "name" : "http://www.fortiguardcenter.com/advisory/FGA-2008-04.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0144.html",
          "name" : "RHSA-2008:0144",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487760/100/0/threaded",
          "name" : "20080208 Adobe Reader/Acrobat Remote PDF Print Silently Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27641",
          "name" : "27641",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043A.html",
          "name" : "TA08-043A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0425/references",
          "name" : "ADV-2008-0425",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1966/references",
          "name" : "ADV-2008-1966",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9731",
          "name" : "oval:org.mitre.oval:def:9731",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The DOC.print function in the Adobe JavaScript API, as used by Adobe Acrobat and Reader before 8.1.2, allows remote attackers to configure silent non-interactive printing, and trigger the printing of an arbitrary number of copies of a document.  NOTE: this issue might be subsumed by CVE-2008-0655."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-11T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0668",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnome",
            "product" : {
              "product_data" : [ {
                "product_name" : "gnumeric",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.91",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=208356",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=208356",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://bugzilla.gnome.org/show_bug.cgi?id=505330",
          "name" : "http://bugzilla.gnome.org/show_bug.cgi?id=505330",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00001.html",
          "name" : "SUSE-SR:2008:016",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28725/",
          "name" : "28725",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28799",
          "name" : "28799",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28948",
          "name" : "28948",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29702",
          "name" : "29702",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29896",
          "name" : "29896",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31339",
          "name" : "31339",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200802-05.xml",
          "name" : "GLSA-200802-05",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1546",
          "name" : "DSA-1546",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gnome.org/projects/gnumeric/announcements/1.8/gnumeric-1.8.1.shtml",
          "name" : "http://www.gnome.org/projects/gnumeric/announcements/1.8/gnumeric-1.8.1.shtml",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:056",
          "name" : "MDVSA-2008:056",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27536",
          "name" : "27536",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-604-1",
          "name" : "USN-604-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0462",
          "name" : "ADV-2008-0462",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00114.html",
          "name" : "FEDORA-2008-1313",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00227.html",
          "name" : "FEDORA-2008-1403",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file containing XLS HLINK opcodes, possibly because of an integer signedness error that leads to an integer overflow.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:fedora:7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:fedora:8:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:gnome:gnumeric:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "1.7.91"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-11T21:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0669",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sift",
            "product" : {
              "product_data" : [ {
                "product_name" : "unity",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28841",
          "name" : "28841",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27684",
          "name" : "27684",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search.cgi in Sift Unity allows remote attackers to inject arbitrary web script or HTML via the qt parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sift:unity:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0670",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_noticias",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27691",
          "name" : "27691",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5081",
          "name" : "5081",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Noticias (com_noticias) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detalhe action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_noticias:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0671",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tintin",
            "product" : {
              "product_data" : [ {
                "product_name" : "tintin++",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.97.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "wintin++",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.97.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/rintintin-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/rintintin-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28833",
          "name" : "28833",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-201111-07.xml",
          "name" : "GLSA-201111-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3632",
          "name" : "3632",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487687/100/0/threaded",
          "name" : "20080206 Chat vulnerabilities in TinTin++ 1.97.9",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27660",
          "name" : "27660",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0449",
          "name" : "ADV-2008-0449",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the add_line_buffer function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to execute arbitrary code via a long chat message, related to conversion from LF to CRLF."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tintin:tintin\\+\\+:1.97.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tintin:wintin\\+\\+:1.97.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0672",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tintin",
            "product" : {
              "product_data" : [ {
                "product_name" : "tintin++",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.97.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "wintin++",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.97.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/rintintin-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/rintintin-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28833",
          "name" : "28833",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-201111-07.xml",
          "name" : "GLSA-201111-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3632",
          "name" : "3632",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487687/100/0/threaded",
          "name" : "20080206 Chat vulnerabilities in TinTin++ 1.97.9",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27660",
          "name" : "27660",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0449",
          "name" : "ADV-2008-0449",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The process_chat_input function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to cause a denial of service (application crash) via a YES message without a newline character, which triggers a NULL dereference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tintin:tintin\\+\\+:1.97.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tintin:wintin\\+\\+:1.97.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0673",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tintin",
            "product" : {
              "product_data" : [ {
                "product_name" : "tintin++",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.97.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "wintin++",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.97.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/rintintin-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/rintintin-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28833",
          "name" : "28833",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-201111-07.xml",
          "name" : "GLSA-201111-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3632",
          "name" : "3632",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487687/100/0/threaded",
          "name" : "20080206 Chat vulnerabilities in TinTin++ 1.97.9",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27660",
          "name" : "27660",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0449",
          "name" : "ADV-2008-0449",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "TinTin++ 1.97.9 and WinTin++ 1.97.9 open files on the basis of an inbound file-transfer request, before the user has an opportunity to decline the request, which allows remote attackers to truncate arbitrary files in the top level of a home directory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tintin:tintin\\+\\+:1.97.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tintin:wintin\\+\\+:1.97.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0674",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pcre",
            "product" : {
              "product_data" : [ {
                "product_name" : "pcre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://ftp.gnome.org/pub/gnome/sources/glib/2.14/glib-2.14.6.news",
          "name" : "http://ftp.gnome.org/pub/gnome/sources/glib/2.14/glib-2.14.6.news",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html",
          "name" : "APPLE-SA-2008-07-31",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html",
          "name" : "APPLE-SA-2008-10-09",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html",
          "name" : "APPLE-SA-2009-08-05-1",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00008.html",
          "name" : "SUSE-SR:2008:004",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://pcre.org/changelog.txt",
          "name" : "http://pcre.org/changelog.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28923",
          "name" : "28923",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28957",
          "name" : "28957",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28960",
          "name" : "28960",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28985",
          "name" : "28985",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28996",
          "name" : "28996",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29027",
          "name" : "29027",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29048",
          "name" : "29048",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29175",
          "name" : "29175",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29267",
          "name" : "29267",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29282",
          "name" : "29282",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30048",
          "name" : "30048",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30345",
          "name" : "30345",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31326",
          "name" : "31326",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32222",
          "name" : "32222",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32746",
          "name" : "32746",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/36096",
          "name" : "36096",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-24.xml",
          "name" : "GLSA-200803-24",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200811-05.xml",
          "name" : "GLSA-200811-05",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT3216",
          "name" : "http://support.apple.com/kb/HT3216",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT3757",
          "name" : "http://support.apple.com/kb/HT3757",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0086",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0086",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0086",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0086",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0176",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0176",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1499",
          "name" : "DSA-1499",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:053",
          "name" : "MDVSA-2008:053",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2008/05/02/2",
          "name" : "[oss-security] 20080502 CVE Request (PHP)",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/ChangeLog-5.php",
          "name" : "http://www.php.net/ChangeLog-5.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488927/100/0/threaded",
          "name" : "20080228 rPSA-2008-0086-1 pcre",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/492535/100/0/threaded",
          "name" : "20080523 rPSA-2008-0176-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27786",
          "name" : "27786",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29009",
          "name" : "29009",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/31681",
          "name" : "31681",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1022674",
          "name" : "1022674",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA09-218A.html",
          "name" : "TA09-218A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0570",
          "name" : "ADV-2008-0570",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0592",
          "name" : "ADV-2008-0592",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1412",
          "name" : "ADV-2008-1412",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2268",
          "name" : "ADV-2008-2268",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2780",
          "name" : "ADV-2008-2780",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2009/2172",
          "name" : "ADV-2009-2172",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=431660",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=431660",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40505",
          "name" : "pcre-characterclass-bo(40505)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2223",
          "name" : "https://issues.rpath.com/browse/RPL-2223",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2503",
          "name" : "https://issues.rpath.com/browse/RPL-2503",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/581-1/",
          "name" : "USN-581-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00371.html",
          "name" : "FEDORA-2008-1533",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00632.html",
          "name" : "FEDORA-2008-1783",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00181.html",
          "name" : "FEDORA-2008-1842",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in PCRE before 7.6 allows remote attackers to execute arbitrary code via a regular expression containing a character class with a large number of characters with Unicode code points greater than 255."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pcre:pcre:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-18T23:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0675",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "the_everything_development_company",
            "product" : {
              "product_data" : [ {
                "product_name" : "the_everything_development_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "pre-1.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3631",
          "name" : "3631",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487436/100/0/threaded",
          "name" : "20080201 The Everything Development System - SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27569",
          "name" : "27569",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5037",
          "name" : "5037",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in cms/index.pl in The Everything Development Engine in The Everything Development System Pre-1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the node_id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:the_everything_development_company:the_everything_development_engine:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "pre-1.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0676",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "a-blog",
            "product" : {
              "product_data" : [ {
                "product_name" : "a-blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27594",
          "name" : "27594",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5050",
          "name" : "5050",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search.php in A-Blog 2 allows remote attackers to inject arbitrary web script or HTML via the words parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:a-blog:a-blog:2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0677",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "a-blog",
            "product" : {
              "product_data" : [ {
                "product_name" : "a-blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27594",
          "name" : "27594",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5050",
          "name" : "5050",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in blog.php in A-Blog 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a news action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:a-blog:a-blog:2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0678",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "blogphp",
            "product" : {
              "product_data" : [ {
                "product_name" : "blogphp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28756",
          "name" : "28756",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27591",
          "name" : "27591",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5042",
          "name" : "5042",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in BlogPHP 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a page action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:blogphp:blogphp:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0679",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "blogphp",
            "product" : {
              "product_data" : [ {
                "product_name" : "blogphp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28756",
          "name" : "28756",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27591",
          "name" : "27591",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5042",
          "name" : "5042",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in BlogPHP 2.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:blogphp:blogphp:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0680",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microtik",
            "product" : {
              "product_data" : [ {
                "product_name" : "routeros",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://hellknights.void.ru/shados/snmp_sploit.c",
          "name" : "http://hellknights.void.ru/shados/snmp_sploit.c",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28762",
          "name" : "28762",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27599",
          "name" : "27599",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0399",
          "name" : "ADV-2008-0399",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5054",
          "name" : "5054",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SNMPd in MikroTik RouterOS 3.2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP SET request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:microtik:routeros:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2017-10-04T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0681",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpshop",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpshop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3628",
          "name" : "3628",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487435/100/0/threaded",
          "name" : "20080202 phpShop <= v 0.8.1 Remote SQL injection / Filter Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27570",
          "name" : "27570",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5041",
          "name" : "5041",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in PHPShop 0.8.1 allows remote attackers to execute arbitrary SQL commands via the product_id parameter, as demonstrated by a shop/flypage action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpshop:phpshop:0.8.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0682",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordspew",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.85",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.91",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.92",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.93",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.94",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.95",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.021",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.022",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.71",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://pierre.sudarovich.free.fr/index.php/2006/02/28/ajax-shoutbox/",
          "name" : "http://pierre.sudarovich.free.fr/index.php/2006/02/28/ajax-shoutbox/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28767",
          "name" : "28767",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27583",
          "name" : "27583",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5039",
          "name" : "5039",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.85:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.91:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.92:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.93:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.94:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:2.95:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.021:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.022:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:3.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordspew:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.71"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0683",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "st_newsletter_plugin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27586",
          "name" : "27586",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5053",
          "name" : "5053",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:st_newsletter_plugin:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0684",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "itechscripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "itechclassifieds",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120197273611835&w=2",
          "name" : "20080201 ITech Classifieds Multiple Remote  Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28773",
          "name" : "28773",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27574",
          "name" : "27574",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to inject arbitrary web script or HTML via the CatID parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:itechscripts:itechclassifieds:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0685",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "itechscripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "itechclassifieds",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120197273611835&w=2",
          "name" : "20080201 ITech Classifieds Multiple Remote  Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28773",
          "name" : "28773",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27574",
          "name" : "27574",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:itechscripts:itechclassifieds:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0686",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_neoreferences",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_neoreferences",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28736",
          "name" : "28736",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27564",
          "name" : "27564",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40167",
          "name" : "neoreferences-index-sql-injection(40167)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5034",
          "name" : "5034",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_neoreferences:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_neoreferences:1.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_neoreferences:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_neoreferences:1.3.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0687",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "youtube",
            "product" : {
              "product_data" : [ {
                "product_name" : "clone_script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28775",
          "name" : "28775",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3635",
          "name" : "3635",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487432/100/0/threaded",
          "name" : "20080201 Youtube Clone Xross Site Scripting (load_message.php)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27598",
          "name" : "27598",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in siteadmin/editor_files/includes/load_message.php in the Youtube Clone Script allows remote attackers to inject arbitrary web script or HTML via the lang[please_wait] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:youtube:clone_script:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0688",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "smartscript",
            "product" : {
              "product_data" : [ {
                "product_name" : "domain_trader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28774",
          "name" : "28774",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3633",
          "name" : "3633",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487433/100/0/threaded",
          "name" : "20080202 Domain Trader v2.0 Xss Vulnerable",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27571",
          "name" : "27571",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in catalog.php in Smartscript Domain Trader 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a viewcategory action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smartscript:domain_trader:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0689",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_marketplace",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1-pl1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27600",
          "name" : "27600",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5055",
          "name" : "5055",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Marketplace (com_marketplace) 1.1.1 and 1.1.1-pl1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_category action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_marketplace:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_marketplace:1.1.1-pl1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0690",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_directory",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27585",
          "name" : "27585",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5047",
          "name" : "5047",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewcat action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_directory:2.3.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0691",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "simon_elvery",
            "product" : {
              "product_data" : [ {
                "product_name" : "wp-footnotes",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wp-footnotes",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28772",
          "name" : "28772",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3634",
          "name" : "3634",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487430/100/0/threaded",
          "name" : "20080201 Wordpress Pluging wp-footnotes 2.2 (admin_panel.php) Multiple Vulnerabilites",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27572",
          "name" : "27572",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40218",
          "name" : "wpfootnotes-adminpanel-security-bypass(40218)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in admin_panel.php in the Simon Elvery WP-Footnotes 2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) wp_footnotes_current_settings[priority], (2) wp_footnotes_current_settings[style_rules], (3) wp_footnotes_current_settings[pre_footnotes], and (4) wp_footnotes_current_settings[post_footnotes] parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:simon_elvery:wp-footnotes:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wp-footnotes:2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0692",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "itechscripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "itechbids",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3_gold",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28780",
          "name" : "28780",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27601",
          "name" : "27601",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5056",
          "name" : "5056",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary SQL commands via the item_id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:itechscripts:itechbids:3_gold:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:itechscripts:itechbids:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0693",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "print_manager_plus",
            "product" : {
              "product_data" : [ {
                "product_name" : "client_billing_and_authentication",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.127.16",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/pqcorez-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/pqcorez-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28741",
          "name" : "28741",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27604",
          "name" : "27604",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0407",
          "name" : "ADV-2008-0407",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in PQCore.exe in Print Manager Plus 2008 Client Billing and Authentication 7.0.127.16 allows remote attackers to cause a denial of service (service outage) via a series of long packets to TCP port 48101."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:print_manager_plus:client_billing_and_authentication:7.0.127.16:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0694",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "os_400",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "v5r3m0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v5r4m0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28744",
          "name" : "28744",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27595",
          "name" : "27595",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0397",
          "name" : "ADV-2008-0397",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=nas22f5a0f082f6821c4862573e10041f7bd",
          "name" : "SE31823",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the HTTP Server in IBM OS/400 V5R3M0 and V5R4M0 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:os_400:v5r3m0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:os_400:v5r4m0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0695",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bookmarkx",
            "product" : {
              "product_data" : [ {
                "product_name" : "script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://www.exploit-db.com/exploits/5040",
          "name" : "5040",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in BookmarkX script 2007 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a showtopic action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bookmarkx:script:2007:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0696",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "db2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.2_fixpack15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT",
          "name" : "ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28771",
          "name" : "28771",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0401",
          "name" : "ADV-2008-0401",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg1IZ07337",
          "name" : "IZ07337",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2_fixpack15:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0697",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "db2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.2_fixpack15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT",
          "name" : "ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28771",
          "name" : "28771",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0401",
          "name" : "ADV-2008-0401",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg1IZ03546",
          "name" : "IZ03546",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain root privileges via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2_fixpack15:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0698",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "db2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.2_fixpack15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT",
          "name" : "ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28771",
          "name" : "28771",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27681",
          "name" : "27681",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0401",
          "name" : "ADV-2008-0401",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg1IZ05496",
          "name" : "IZ05496",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, and an impact probably involving \"invalid memory access.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2_fixpack15:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0699",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "db2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT",
          "name" : "ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/41795",
          "name" : "41795",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://secunia.com/advisories/28771",
          "name" : "28771",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29022",
          "name" : "29022",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29784",
          "name" : "29784",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.appsecinc.com/resources/alerts/db2/2008-02.shtml",
          "name" : "http://www.appsecinc.com/resources/alerts/db2/2008-02.shtml",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/491075/100/0/threaded",
          "name" : "20080418 Team SHATTER Security Advisory: IBM DB2 UDB Arbitrary code execution in ADMIN_SP_C/ADMIN_SP_C2 procedures",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0401",
          "name" : "ADV-2008-0401",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06972",
          "name" : "IZ06972",
          "refsource" : "AIXAPAR",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06973",
          "name" : "IZ06973",
          "refsource" : "AIXAPAR",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg1IZ10917",
          "name" : "IZ10917",
          "refsource" : "AIXAPAR",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Fixpak 16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unspecified attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp11:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp12:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp13:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp14:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp15:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp16:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:8.2:fp9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.1:fp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.1:fp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.1:fp2a:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.1:fp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.1:fp3a:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.1:fp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2018-11-01T15:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0700",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "crux_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "cruxcms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://downloads.securityfocus.com/vulnerabilities/exploits/27588.html",
          "name" : "http://downloads.securityfocus.com/vulnerabilities/exploits/27588.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27588",
          "name" : "27588",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search.php in Crux Software CruxCMS 3.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:crux_software:cruxcms:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0701",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "magnolia",
            "product" : {
              "product_data" : [ {
                "product_name" : "ce",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jira.magnolia.info/browse/MAGNOLIA-2021",
          "name" : "http://jira.magnolia.info/browse/MAGNOLIA-2021",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28745",
          "name" : "28745",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=573088",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=573088",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27608",
          "name" : "27608",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ActivationHandler in Magnolia CE 3.5.x before 3.5.4 does not check permissions during importing, which allows remote attackers to have an unknown impact via activation of a new item, possibly involving addition of arbitrary new content."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:magnolia:ce:3.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:magnolia:ce:3.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:magnolia:ce:3.5.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2008-12-17T06:24Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0702",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "south_river_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "titan_ftp_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.5.549",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.03",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28760",
          "name" : "28760",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3639",
          "name" : "3639",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487431/100/0/threaded",
          "name" : "20080201 Titan FTP Server Remote Heap Overflow (USER/PASS)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27568",
          "name" : "27568",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0393",
          "name" : "ADV-2008-0393",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5036",
          "name" : "5036",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of service (daemon crash or hang) and possibly execute arbitrary code via a long argument to the (1) USER or (2) PASS command, different vectors than CVE-2004-1641."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:south_river_technologies:titan_ftp_server:6.0.5.549:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:south_river_technologies:titan_ftp_server:6.03:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0703",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sflog",
            "product" : {
              "product_data" : [ {
                "product_name" : "sflog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.96",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3629",
          "name" : "3629",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487368/100/0/threaded",
          "name" : "20080131 sflog! 0.96 remote file disclosure vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27541",
          "name" : "27541",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40115",
          "name" : "sflog-blog-index-directory-traversal(40115)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5027",
          "name" : "5027",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) permalink or (2) section parameter to index.php, possibly involving includes/entries.inc.php and other files included by index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sflog:sflog:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.96"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0704",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "open_vms_tcp-ip_services",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.4",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "5.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29566",
          "name" : "29566",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28486",
          "name" : "28486",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019727",
          "name" : "1019727",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1009",
          "name" : "ADV-2008-1009",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01414022",
          "name" : "SSRT071479",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41519",
          "name" : "openvms-sshserver-unauthorized-access(41519)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the SSH server in HP OpenVMS TCP/IP Services on OpenVMS on the Alpha platform with 5.4 before ECO 7, and on the Integrity and Alpha platforms with 5.5 before ECO 3 and 5.6 before ECO 2, allows remote attackers to obtain unspecified access via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:hp:alpha:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:hp:open_vms_tcp-ip_services:*:eco_6:*:*:*:*:*:*",
            "versionEndIncluding" : "5.4"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:hp:alpha:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:hp:integrity:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:hp:open_vms_tcp-ip_services:*:eco_2:*:*:*:*:*:*",
            "versionEndIncluding" : "5.5"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:hp:open_vms_tcp-ip_services:*:eco_1:*:*:*:*:*:*",
            "versionEndIncluding" : "5.6"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-28T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0705",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2008. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0706",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "compaq",
            "product" : {
              "product_data" : [ {
                "product_name" : "presario_a900",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "presario_c700",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "g7000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "hpqflash_for_hp_notebook_system_bios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "f.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "f.2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "f.2e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "f.2f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "f.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "f.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "f.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "f.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "f.30",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120672270224094&w=2",
          "name" : "HPSBGN02319",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019730",
          "name" : "1019730",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28495",
          "name" : "28495",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1043/references",
          "name" : "ADV-2008-1043",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41521",
          "name" : "compaq-pcbios-security-bypass(41521)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the BIOS F.26 and earlier for the HP Compaq Notebook PC allows physically proximate attackers to obtain privileged access via unspecified vectors, possibly involving an authentication bypass of the power-on password."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compaq:presario_a900:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compaq:presario_c700:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:g7000:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:hpqflash_for_hp_notebook_system_bios:f.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:hpqflash_for_hp_notebook_system_bios:f.2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:hpqflash_for_hp_notebook_system_bios:f.2e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:hpqflash_for_hp_notebook_system_bios:f.2f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:hpqflash_for_hp_notebook_system_bios:f.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:hpqflash_for_hp_notebook_system_bios:f.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:hpqflash_for_hp_notebook_system_bios:f.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:hpqflash_for_hp_notebook_system_bios:f.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:hpqflash_for_hp_notebook_system_bios:f.30:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-31T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0707",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "storageworks_library_and_tape_tools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5_sr1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29442",
          "name" : "29442",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019651",
          "name" : "1019651",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28314",
          "name" : "28314",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0926/references",
          "name" : "ADV-2008-0926",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41337",
          "name" : "hp-storageworks-unspecified-priv-escalation(41337)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www12.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01399648",
          "name" : "SSRT080029",
          "refsource" : "HP",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "HP StorageWorks Library and Tape Tools (LTT) before 4.5 SR1 on HP-UX B.11.11 and B.11.23 allows local users to gain privileges via unspecified vectors."
        }, {
          "lang" : "en",
          "value" : "Link 1015143 requires login"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.23:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:hp:storageworks_library_and_tape_tools:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "4.5_sr1"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-20T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0708",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "442084-b21",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "442085-b21",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "proliant",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "bl20pg4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "bl25pg2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "bl45pg2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "bl260c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "bl460c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "bl465c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "bl465cg5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "bl480c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "bl680cg5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "bl685c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "bl685cg5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "dl120g5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "dl140g3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "dl145g3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "dl160g5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "dl165g5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "dl180",
                    "version_affected" : "="
                  }, {
                    "version_value" : "dl180g5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "dl185g5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "dl320g5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "dl365g5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "dl380g5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "dl385g2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "dl385g5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "dl580g4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "ml110g5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "ml115",
                    "version_affected" : "="
                  }, {
                    "version_value" : "ml115g5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "ml150g3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "ml150g5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "ml310g4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "ml310g5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "ml350g5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "ml370g5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "ml570g4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120732648630458&w=2",
          "name" : "SSRT080032",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019785",
          "name" : "1019785",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41648",
          "name" : "hp-usbfloppydrivekey-weak-security(41648)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "HP USB 2.0 Floppy Drive Key product options (1) 442084-B21 and (2) 442085-B21 for certain HP ProLiant servers contain the (a) W32.Fakerecy and (b) W32.SillyFDC worms, which might be launched if the server does not have up-to-date detection."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:442084-b21:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:442085-b21:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:bl20pg4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:bl25pg2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:bl45pg2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:bl260c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:bl460c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:bl465c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:bl465cg5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:bl480c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:bl680cg5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:bl685c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:bl685cg5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:dl120g5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:dl140g3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:dl145g3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:dl160g5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:dl165g5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:dl180:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:dl180g5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:dl185g5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:dl320g5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:dl365g5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:dl380g5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:dl385g2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:dl385g5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:dl580g4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:ml110g5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:ml115:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:ml115g5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:ml150g3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:ml150g5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:ml310g4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:ml310g5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:ml350g5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:ml370g5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:proliant:ml570g4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-06T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0709",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "select_identity",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.20",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          }, {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01391833",
          "name" : "HPSBMA02317",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29643",
          "name" : "29643",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019746",
          "name" : "1019746",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28558",
          "name" : "28558",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1072/references",
          "name" : "ADV-2008-1072",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41583",
          "name" : "hpselectidentity-useraccount-unauth-access(41583)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to access other user accounts via unknown vectors, a different issue than CVE-2008-0214."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:linux_as3:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:hp:select_identity:4.00:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:linux_as3:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:sun:solaris:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:hp:select_identity:4.01:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:hp:select_identity:4.12:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:hp:select_identity:4.13:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:linux_as3:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:hp:select_identity:4.11:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:linux_as4:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:hp:select_identity:4.20:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-07T17:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0710",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2008. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0711",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "bl860c",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rx2660",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rx3600",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rx6600",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120766789901792&w=2",
          "name" : "SSRT071455",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29718",
          "name" : "29718",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3804",
          "name" : "3804",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28673",
          "name" : "28673",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019795",
          "name" : "1019795",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1132/references",
          "name" : "ADV-2008-1132",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41696",
          "name" : "hp-integrityserver-ilo2mp-console-dos(41696)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the embedded management console in HP iLO-2 Management Processors (iLO-2 MP), as used in Integrity Servers rx2660, rx3600, and rx6600, and Integrity Blade Server model bl860c, allows remote attackers to cause a denial of service via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:bl860c:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:rx2660:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:rx3600:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:rx6600:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-08T18:05Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0712",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "software_update",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.000.009.002",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120907060320901&w=2",
          "name" : "HPSBGN02333",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29966",
          "name" : "29966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28929",
          "name" : "28929",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019922",
          "name" : "1019922",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1356/references",
          "name" : "ADV-2008-1356",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42003",
          "name" : "hpsoftware-hpediag-code-execution(42003)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag.dll in HP Software Update 4.000.009.002 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors.  NOTE: this might overlap CVE-2007-6513."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:software_update:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.000.009.002"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-25T19:05Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0713",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "hp-ux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.31",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01446326",
          "name" : "SSRT071403",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30195",
          "name" : "30195",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29160",
          "name" : "29160",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020005",
          "name" : "1020005",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1475/references",
          "name" : "ADV-2008-1475",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42357",
          "name" : "hpux-ftp-dos(42357)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5289",
          "name" : "oval:org.mitre.oval:def:5289",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the FTP server for HP-UX B.11.11, B.11.23, and B.11.31 allows remote authenticated users to cause a denial of service (FTP server outage) via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.31:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-05-13T20:20Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0714",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mihalism",
            "product" : {
              "product_data" : [ {
                "product_name" : "multi_host",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28803",
          "name" : "28803",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27651",
          "name" : "27651",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40289",
          "name" : "mihalism-users-sql-injection(40289)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5074",
          "name" : "5074",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in users.php in Mihalism Multi Host allows remote attackers to execute arbitrary SQL commands via the username parameter in a lost_password_go action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mihalism:multi_host:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0715",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "acdsee",
            "product" : {
              "product_data" : [ {
                "product_name" : "photo_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28797",
          "name" : "28797",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+AcdSee+Photo+Manager",
          "name" : "http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+AcdSee+Photo+Manager",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0443",
          "name" : "ADV-2008-0443",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in ACDSee Photo Manager 8.1, 9.0, and 10.0 allows user-assisted remote attackers to execute arbitrary code via a malformed XBM file.  NOTE: this might be the same as CVE-2007-6009."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:acdsee:photo_manager:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:acdsee:photo_manager:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:acdsee:photo_manager:10.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T02:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0716",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "altiris_notification_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0_sp3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28832",
          "name" : "28832",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityresponse.symantec.com/avcenter/security/Content/2008.02.06.html",
          "name" : "http://securityresponse.symantec.com/avcenter/security/Content/2008.02.06.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27645",
          "name" : "27645",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019313",
          "name" : "1019313",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0444",
          "name" : "ADV-2008-0444",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The agent in Symantec Altiris Notification Server before 6.0 SP3 R7 allows local users to gain privileges via a \"Shatter\" style attack."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:altiris_notification_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.0_sp3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T02:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0717",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_edge_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28785",
          "name" : "28785",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27665",
          "name" : "27665",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019315",
          "name" : "1019315",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0446",
          "name" : "ADV-2008-0446",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg21294776",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg21294776",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Caching Proxy (CP) 5.1 through 6.1 in IBM WebSphere Edge Server, when CGI mapping rules are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger injection into an error response."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_edge_server:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_edge_server:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_edge_server:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_edge_server:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_edge_server:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_edge_server:6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T02:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0718",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28921",
          "name" : "28921",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-201316-1",
          "name" : "201316",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27773",
          "name" : "27773",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0451",
          "name" : "ADV-2008-0451",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5474",
          "name" : "oval:org.mitre.oval:def:5474",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the USB Mouse STREAMS module (usbms) in Sun Solaris 9 and 10, when 64-bit mode is enabled, allows local users to cause a denial of service (panic) via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10:*:x86:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.7
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0719",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oscommerce",
            "product" : {
              "product_data" : [ {
                "product_name" : "customer_testimonials",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "oscommerce",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28831",
          "name" : "28831",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27664",
          "name" : "27664",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5075",
          "name" : "5075",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote attackers to execute arbitrary SQL commands via the testimonial_id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oscommerce:customer_testimonials:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oscommerce:oscommerce:2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0720",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webmin",
            "product" : {
              "product_data" : [ {
                "product_name" : "usermin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.32",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "webmin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.370",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.390",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forum.aria-security.net/showthread.php?t=511",
          "name" : "http://forum.aria-security.net/showthread.php?t=511",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28827",
          "name" : "28827",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487656/100/0/threaded",
          "name" : "20080206 Tested on Webmin 1.390",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487678/100/0/threaded",
          "name" : "20080206 Re: Tested on Webmin 1.390",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27662",
          "name" : "27662",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0450",
          "name" : "ADV-2008-0450",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Webmin 1.370 and 1.390 and Usermin 1.300 and 1.320 allows remote attackers to inject arbitrary web script or HTML via the search parameter to webmin_search.cgi (aka the search section), and possibly other components accessed through a \"search box\" or \"open file box.\" NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webmin:usermin:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webmin:usermin:1.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webmin:webmin:1.370:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webmin:webmin:1.390:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0721",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_sermon",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27673",
          "name" : "27673",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5076",
          "name" : "5076",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Sermon (com_sermon) 0.2 component for Mambo allows remote attackers to execute arbitrary SQL commands via the gid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_sermon:0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0722",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pagetool",
            "product" : {
              "product_data" : [ {
                "product_name" : "pagetool",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.07",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27653",
          "name" : "27653",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4983",
          "name" : "4983",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in Pagetool 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the search_term parameter in a pagetool_search action.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pagetool:pagetool:1.07:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0723",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "planetluc",
            "product" : {
              "product_data" : [ {
                "product_name" : "mynews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=120232523420188&w=2",
          "name" : "20080206 MyNews 1.6.X HTML/JS Injection Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://marc.info/?l=full-disclosure&m=120235668406688&w=2",
          "name" : "20080207 Re: MyNews 1.6.X HTML/JS Injection Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27652",
          "name" : "27652",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitrary web script or HTML via the hash parameter in an admin action to index.php, a different vulnerability than CVE-2006-2208.1."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:planetluc:mynews:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T02:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0724",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "the_everything_development_company",
            "product" : {
              "product_data" : [ {
                "product_name" : "the_everything_development_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "pre-1.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-255"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3631",
          "name" : "3631",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487436/100/0/threaded",
          "name" : "20080201 The Everything Development System - SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5037",
          "name" : "5037",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Everything Development Engine in The Everything Development System Pre-1.0 and earlier stores passwords in cleartext in a database, which makes it easier for context-dependent attackers to obtain access to user accounts."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:the_everything_development_company:the_everything_development_engine:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "pre-1.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0725",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "titan",
            "product" : {
              "product_data" : [ {
                "product_name" : "ftp_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.5.549",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28760",
          "name" : "28760",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple heap-based buffer overflows in the (1) FTP service and (2) administration service in Titan FTP Server 6.0.5.549 allow remote attackers to cause a denial of service (daemon hang) and possibly execute arbitrary code via a long command.  NOTE: the USER and PASS commands for the FTP service are covered by CVE-2008-0702."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:titan:ftp_server:6.0.5.549:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T02:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0726",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "acrobat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.1",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "acrobat_reader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00007.html",
          "name" : "SUSE-SA:2008:009",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28983",
          "name" : "28983",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29065",
          "name" : "29065",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29205",
          "name" : "29205",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30840",
          "name" : "30840",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-01.xml",
          "name" : "GLSA-200803-01",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-239286-1",
          "name" : "239286",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.adobe.com/support/security/advisories/apsa08-01.html",
          "name" : "http://www.adobe.com/support/security/advisories/apsa08-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.adobe.com/support/security/bulletins/apsb08-13.html",
          "name" : "http://www.adobe.com/support/security/bulletins/apsb08-13.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0144.html",
          "name" : "RHSA-2008:0144",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488000/100/0/threaded",
          "name" : "20080211 ZDI-08-004: Adobe AcrobatReader Javascript for PDF Integer Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1966/references",
          "name" : "ADV-2008-1966",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-004.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-004.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10957",
          "name" : "oval:org.mitre.oval:def:10957",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via crafted arguments to the printSepsWithParams, which triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.1.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0727",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "informix_dynamic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.31.xd8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.31.xd9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.40.tc5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.40.uc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.40.uc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.40.uc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.40.uc5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.40.xd8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.40_xc7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.xc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.xc4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.00.xc7w1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.10.xc2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29272",
          "name" : "29272",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3749",
          "name" : "3749",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489547/100/0/threaded",
          "name" : "20080313 ZDI-08-011: IBM Informix Dynamic Server DBPATH Buffer Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489548/100/0/threaded",
          "name" : "20080313 ZDI-08-012: IBM Informix Dynamic Server Authentication Password Stack Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28198",
          "name" : "28198",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0860",
          "name" : "ADV-2008-0860",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-011/",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-011/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-012/",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-012/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg1IC55207",
          "name" : "IC55207",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg1IC55208",
          "name" : "IC55208",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg1IC55209",
          "name" : "IC55209",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg1IC55210",
          "name" : "IC55210",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41202",
          "name" : "ibm-informix-oninit-dbpath-bo(41202)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41203",
          "name" : "ibm-informix-oninit-bo(41203)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in oninit.exe in IBM Informix Dynamic Server (IDS) 7.x through 11.x allow (1) remote attackers to execute arbitrary code via a long password and (2) remote authenticated users to execute arbitrary code via a long DBPATH value."
        }, {
          "lang" : "en",
          "value" : "All IBM links require software support sign in to view."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:7.31.xd8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:7.31.xd9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.40.tc5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.40.uc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.40.uc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.40.uc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.40.uc5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.40.xd8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.40_xc7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:10.0.xc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:10.0.xc4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:10.00.xc7w1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:11.10.xc2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 8.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0728",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clamav",
            "product" : {
              "product_data" : [ {
                "product_name" : "clamav",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.60p",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.65",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.66",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.67",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.67-1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.68",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.68.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.70",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.71",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.72",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.73",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.74",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.75",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.75.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.80",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.80_rc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.81",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.82",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.83",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.84",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.85",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.85.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.86",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.86.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.86.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.87",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.87.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.7_p0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.7_p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90.1_p0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90.2_p0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90.3_p0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90.3_p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.91",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.91.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.91.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.91.2_p0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.92",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.92_p0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=209915",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=209915",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://kolab.org/security/kolab-vendor-notice-19.txt",
          "name" : "http://kolab.org/security/kolab-vendor-notice-19.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00008.html",
          "name" : "SUSE-SR:2008:004",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28907",
          "name" : "28907",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29001",
          "name" : "29001",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29026",
          "name" : "29026",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29048",
          "name" : "29048",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29060",
          "name" : "29060",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200802-09.xml",
          "name" : "GLSA-200802-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=575703",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=575703",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/512985d2cd3090bfb93dcb7b551179cf.html",
          "name" : "http://support.novell.com/techcenter/psdb/512985d2cd3090bfb93dcb7b551179cf.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:088",
          "name" : "MDVSA-2008:088",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0503",
          "name" : "ADV-2008-0503",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0606",
          "name" : "ADV-2008-0606",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40474",
          "name" : "clamav-mewc-heap-corruption(40474)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The unmew11 function in libclamav/mew.c in libclamav in ClamAV before 0.92.1 has unknown impact and attack vectors that trigger \"heap corruption.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.05:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.8:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.9:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.14:pre:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.60p:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.65:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.66:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.67:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.67-1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.68:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.68.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.70:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.70:rc:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.71:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.72:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.73:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.74:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.75:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.75.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.80:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.80:rc:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.80:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.80:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.80:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.80:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.80_rc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.81:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.81:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.82:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.83:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.84:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.84:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.84:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.85:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.85.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.86:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.86:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.86.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.86.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.87:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.87.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.88:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.88.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.88.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.88.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.88.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.88.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.88.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.88.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.88.7_p0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.88.7_p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.90:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.90:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.90:rc1.1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.90:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.90:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.90.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.90.1_p0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.90.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.90.2_p0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.90.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.90.3_p0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.90.3_p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.91:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.91:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.91:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.91.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.91.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.91.2_p0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.92"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:0.92_p0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T20:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0729",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mobile_safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3630",
          "name" : "3630",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487607/100/0/threaded",
          "name" : "20080205 Apple iPhone 1.1.3 remote DoS exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/492225/100/0/threaded",
          "name" : "20080519 Re: Apple iPhone 1.1.3 remote DoS exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27442",
          "name" : "27442",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39998",
          "name" : "iphone-mobilesafari-dos(39998)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4978",
          "name" : "4978",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion and device crash) via certain JavaScript code that constructs a long string and an array containing long string elements, possibly a related issue to CVE-2006-3677.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:apple:iphone:1.1.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:apple:iphone:1.1.3:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:mobile_safari:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0730",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28931",
          "name" : "28931",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-201315-1",
          "name" : "201315",
          "refsource" : "SUNALERT",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27770",
          "name" : "27770",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0452",
          "name" : "ADV-2008-0452",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5545",
          "name" : "oval:org.mitre.oval:def:5545",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The (1) Simplified Chinese, (2) Traditional Chinese, (3) Korean, and (4) Thai language input methods in Sun Solaris 10 create files and directories with weak permissions under (a) .iiim/le and (b) .Xlocale in home directories, which might allow local users to write to, or read from, the home directories of other users."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10:*:*:ko:*:*:sparc:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10:*:*:ko:*:*:x86:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10:*:*:th:*:*:sparc:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10:*:*:th:*:*:x86:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10:*:*:zh:*:*:sparc:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10:*:*:zh:*:*:x86:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T21:00Z",
    "lastModifiedDate" : "2017-11-21T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0731",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "novell",
            "product" : {
              "product_data" : [ {
                "product_name" : "apparmor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          }, {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html",
          "name" : "SUSE-SA:2008:006",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28806",
          "name" : "28806",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Linux kernel before 2.6.18.8-0.8 in SUSE openSUSE 10.2 does not properly handle failure of an AppArmor change_hat system call, which might allow attackers to trigger the unconfining of an apparmored task."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "2.6.18.8"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:open_suse:10.2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:novell:apparmor:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T21:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0732",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "geronimo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-59"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html",
          "name" : "SUSE-SR:2008:003",
          "refsource" : "SUSE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28838",
          "name" : "28838",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or directories."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apache:geronimo:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T21:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0733",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cs_team",
            "product" : {
              "product_data" : [ {
                "product_name" : "counter_strike_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/487988/100/0/threaded",
          "name" : "20080212 Kommentare zum Download script SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27747",
          "name" : "27747",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40520",
          "name" : "counterstrikeportals-index-sql-injection(40520)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in CS Team Counter Strike Portals allows remote attackers to execute arbitrary SQL commands via the id parameter, as demonstrated using the downloads page."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cs_team:counter_strike_portal:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0734",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "limbo_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "limbo_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.4.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27710",
          "name" : "27710",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40415",
          "name" : "limbo-admin-sql-injection(40415)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5088",
          "name" : "5088",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in class_auth.php in Limbo CMS 1.0.4.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the cuid cookie parameter to admin.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:limbo_cms:limbo_cms:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.4.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T01:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0735",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "auracms",
            "product" : {
              "product_data" : [ {
                "product_name" : "auracms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28950",
          "name" : "28950",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27764",
          "name" : "27764",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5105",
          "name" : "5105",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the albums parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:auracms:auracms:2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T01:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0736",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "shoppingtree",
            "product" : {
              "product_data" : [ {
                "product_name" : "candypress_store",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1.26",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3600",
          "name" : "3600",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&PN=1",
          "name" : "http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&PN=1",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487058/100/0/threaded",
          "name" : "20080125 [CandyPress] eCommerce suite (SQL Injection + XSS + Path Disclosure)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27454",
          "name" : "27454",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0314",
          "name" : "ADV-2008-0314",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39941",
          "name" : "ecommerce-sashipfedexmeter-path-disclosure(39941)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4988",
          "name" : "4988",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a certain value of the FedExAccount parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shoppingtree:candypress_store:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shoppingtree:candypress_store:4.1.1.26:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0737",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "shoppingtree",
            "product" : {
              "product_data" : [ {
                "product_name" : "candypress_store",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1.26",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28662",
          "name" : "28662",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3600",
          "name" : "3600",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&PN=1",
          "name" : "http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&PN=1",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487058/100/0/threaded",
          "name" : "20080125 [CandyPress] eCommerce suite (SQL Injection + XSS + Path Disclosure)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27454",
          "name" : "27454",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0314",
          "name" : "ADV-2008-0314",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4988",
          "name" : "4988",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and other 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the helpfield parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shoppingtree:candypress_store:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shoppingtree:candypress_store:4.1.1.26:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0738",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "shoppingtree",
            "product" : {
              "product_data" : [ {
                "product_name" : "candypress_store",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "4.1.1.26",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28662",
          "name" : "28662",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&PN=1",
          "name" : "http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&PN=1",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0314",
          "name" : "ADV-2008-0314",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idcust parameter to (a) ajax_getTiers.asp and (b) ajax_getCust.asp in ajax/, and the (2) tableName parameter to (c) ajax/ajax_tableFields.asp.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shoppingtree:candypress_store:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shoppingtree:candypress_store:4.1.1.26:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T01:00Z",
    "lastModifiedDate" : "2009-08-20T05:13Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0739",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "shoppingtree",
            "product" : {
              "product_data" : [ {
                "product_name" : "candypress_store",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "4.1.1.26",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28662",
          "name" : "28662",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&PN=1",
          "name" : "http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&PN=1",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0314",
          "name" : "ADV-2008-0314",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and earlier 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the FedExAccount parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shoppingtree:candypress_store:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shoppingtree:candypress_store:4.1.1.26:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T01:00Z",
    "lastModifiedDate" : "2009-08-20T05:13Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0740",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.2.24",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/42878",
          "name" : "42878",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27400",
          "name" : "27400",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0241",
          "name" : "ADV-2008-0241",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg1PK48785",
          "name" : "PK48785",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg27006876",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg27006876",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg27007951",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg27007951",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) and 6.1 before Fix Pack 15 (6.1.0.15) writes unspecified cleartext information to http_plugin.log, which might allow local users to obtain sensitive information by reading this file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.0.2.24"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T01:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0741",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.2.24",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          }, {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28588",
          "name" : "28588",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019254",
          "name" : "1019254",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27400",
          "name" : "27400",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0241",
          "name" : "ADV-2008-0241",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?rs=0&dc=DB550&q1=PK52709&uid=swg1PK58871&loc=en_US&cs=utf-8&lang=",
          "name" : "PK52709",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg27006876",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg27006876",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) has unknown impact and attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.0.2.24"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T01:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0742",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "powerscripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "powernews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3647",
          "name" : "3647",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487773/100/0/threaded",
          "name" : "20080208 [DSECRG-08-014] Multiple LFI in PowerNews (Newsscript) 2.5.6",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27688",
          "name" : "27688",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5082",
          "name" : "5082",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include arbitrary files via a .. (dot dot) in the (1) subpage parameter in (a) categories.inc.php, (b) news.inc.php, (c) other.inc.php, (d) permissions.inc.php, (e) templates.inc.php, and (f) users.inc.php in pnadmin/; and (2) the page parameter to (g) pnadmin/index.php.  NOTE: vector 2 is only exploitable by administrators."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:powerscripts:powernews:2.5.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0743",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joovili",
            "product" : {
              "product_data" : [ {
                "product_name" : "joovili",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3640",
          "name" : "3640",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487779/100/0/threaded",
          "name" : "20080207 Joovili <= v.2.1 (members_help.php) Remote File &#304;nclude Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27693",
          "name" : "27693",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in members_help.php in Joovili 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the hlp parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joovili:joovili:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0744",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "preprojects.com",
            "product" : {
              "product_data" : [ {
                "product_name" : "pre_hotels_&_resorts_management_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3644",
          "name" : "3644",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487053/100/100/threaded",
          "name" : "20080124 Pre Hotel and Resorts reservation portal login bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27450",
          "name" : "27450",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39935",
          "name" : "prehotel-login-sql-injection(39935)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in user_login.asp in PreProjects.com Pre Hotels & Resorts Management System allows remote attackers to execute arbitrary SQL commands via the login page."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:preprojects.com:pre_hotels_\\&_resorts_management_system:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0745",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "domphp",
            "product" : {
              "product_data" : [ {
                "product_name" : "domphp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.82",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27712",
          "name" : "27712",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5089",
          "name" : "5089",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:domphp:domphp:0.82:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0746",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.attrition.org/pipermail/vim/2008-February/001901.html",
          "name" : "20080208 Mambo Component com_gallery Remote SQL Injection Vulnerability",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2008-February/001902.html",
          "name" : "20080208 Mambo Component com_gallery Remote SQL Injection Vulnerability",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27695",
          "name" : "27695",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5084",
          "name" : "5084",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_gallery:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_gallery:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0747",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cowon_america",
            "product" : {
              "product_data" : [ {
                "product_name" : "jetaudio_basic",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28855",
          "name" : "28855",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3642",
          "name" : "3642",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487806/100/0/threaded",
          "name" : "20080208 jetAudio <= 7.0.5 (.ASX) Remote Stack Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27698",
          "name" : "27698",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0502",
          "name" : "ADV-2008-0502",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5085",
          "name" : "5085",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute arbitrary code via a long URL in a .asx file, a different vulnerability than CVE-2007-5487."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cowon_america:jetaudio_basic:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.0.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-13T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0748",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sony",
            "product" : {
              "product_data" : [ {
                "product_name" : "axruploadserver_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0.38",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "imagestation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28854",
          "name" : "28854",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3648",
          "name" : "3648",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487802/100/0/threaded",
          "name" : "20080208 Buffer Overflow Vulnerability in AxRUploadServer.dll, Activex Method (SetLogging)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487805/100/0/threaded",
          "name" : "20080208 Re: Buffer Overflow Vulnerability in AxRUploadServer.dll, Activex Method (SetLogging)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27715",
          "name" : "27715",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0483",
          "name" : "ADV-2008-0483",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5086",
          "name" : "5086",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5100",
          "name" : "5100",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote attackers to execute arbitrary code via a long argument to the SetLogging method.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sony:axruploadserver_activex_control:1.0.0.38:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sony:imagestation:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0749",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "calimero.cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "calimero.cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://downloads.securityfocus.com/vulnerabilities/exploits/27690.html",
          "name" : "http://downloads.securityfocus.com/vulnerabilities/exploits/27690.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/ref/41/41573-calimero.txt",
          "name" : "http://osvdb.org/ref/41/41573-calimero.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/41573",
          "name" : "41573",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27690",
          "name" : "27690",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in Calimero.CMS 3.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a calimero_webpage action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:calimero.cms:calimero.cms:3.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-13T20:00Z",
    "lastModifiedDate" : "2009-08-25T05:09Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0750",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "husrev",
            "product" : {
              "product_data" : [ {
                "product_name" : "blackboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28842",
          "name" : "28842",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3641",
          "name" : "3641",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487780/100/200/threaded",
          "name" : "20080207 Husrev Forums v2.0.1:PoWerBoard (tr) (id) Remote SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487781/100/0/threaded",
          "name" : "20080207 Blackboard (id) Remote SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27714",
          "name" : "27714",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40368",
          "name" : "blackboard-philboardforum-sql-injection(40368)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in philboard_forum.asp in Husrev BlackBoard 2.0.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:husrev:blackboard:2.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0751",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "s9y",
            "product" : {
              "product_data" : [ {
                "product_name" : "serendipity_event_freetag",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.70",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.88",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.95",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blog.s9y.org/archives/190-Freetag-plugin-updated-to-prevent-XSS.html",
          "name" : "http://blog.s9y.org/archives/190-Freetag-plugin-updated-to-prevent-XSS.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060122.html",
          "name" : "20080208 Serendipity Freetag-plugin XSS vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28852",
          "name" : "28852",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.bitsploit.de/uploads/Code/200802080000/",
          "name" : "http://www.bitsploit.de/uploads/Code/200802080000/",
          "refsource" : "MISC",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27697",
          "name" : "27697",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40376",
          "name" : "serendipity-freetag-xss(40376)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Freetag before 2.96 plugin for S9Y Serendipity, when using Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to plugin/tag/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:s9y:serendipity_event_freetag:*:*:*:*:*:*:*:*",
            "versionEndExcluding" : "2.96"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-13T20:00Z",
    "lastModifiedDate" : "2020-06-23T13:15Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0752",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_neogallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_neogallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27692",
          "name" : "27692",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40357",
          "name" : "neogallery-index-sql-injection(40357)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5083",
          "name" : "5083",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_neogallery:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_neogallery:1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T20:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0753",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vwar",
            "product" : {
              "product_data" : [ {
                "product_name" : "virtual_war",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3643",
          "name" : "3643",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487900/100/0/threaded",
          "name" : "20080210 Vwar 1.5.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27722",
          "name" : "27722",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vwar:virtual_war:1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0754",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_rapidrecipe",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28883",
          "name" : "28883",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3649",
          "name" : "3649",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487901/100/0/threaded",
          "name" : "20080210 Default Multiple Joomla! Component com_rapidrecipe \"user_id=\" Remote SQL Inj.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27724",
          "name" : "27724",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in index.php in the Rapid Recipe (com_rapidrecipe) 1.6.5 component for Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a showuser action or (2) the category_id parameter in a viewcategorysrecipes action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_rapidrecipe:1.6.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0755",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cyan_soft",
            "product" : {
              "product_data" : [ {
                "product_name" : "cyanprintip_basic",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10.1030",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "cyanprintip_easy_opi",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10.1030",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "cyanprintip_professional",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10.1030",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "cyanprintip_standard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10.940",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "cyanprintip_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10.836",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "opium4_opi_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10.1028",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/cyanuro-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/cyanuro-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28870",
          "name" : "28870",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487955/100/0/threaded",
          "name" : "20080211 Format string and DoS in Opium OPI and cyanPrintIP servers 4.10.x",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27728",
          "name" : "27728",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27734",
          "name" : "27734",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0498",
          "name" : "ADV-2008-0498",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the ReportSysLogEvent function in the LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; might allow remote attackers to execute arbitrary code via format string specifiers in the queue name in a request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cyan_soft:cyanprintip_basic:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.10.1030"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cyan_soft:cyanprintip_easy_opi:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.10.1030"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cyan_soft:cyanprintip_professional:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.10.1030"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cyan_soft:cyanprintip_standard:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.10.940"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cyan_soft:cyanprintip_workstation:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.10.836"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cyan_soft:opium4_opi_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.10.1028"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0756",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cyan_soft",
            "product" : {
              "product_data" : [ {
                "product_name" : "cyanprintip_basic",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10.1030",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "cyanprintip_easy_opi",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10.1030",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "cyanprintip_professional",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10.1030",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "cyanprintip_standard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10.940",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "cyanprintip_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10.836",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "opium4_opi_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10.1028",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/cyanuro-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/cyanuro-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28870",
          "name" : "28870",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487955/100/0/threaded",
          "name" : "20080211 Format string and DoS in Opium OPI and cyanPrintIP servers 4.10.x",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27728",
          "name" : "27728",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27734",
          "name" : "27734",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0498",
          "name" : "ADV-2008-0498",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; allows remote attackers to cause a denial of service (daemon crash) via a connection that begins with (1) a \"Send queue state\" LPD command 3 or (2) a \"Send queue state\" LPD command 4."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cyan_soft:cyanprintip_basic:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.10.1030"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cyan_soft:cyanprintip_easy_opi:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.10.1030"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cyan_soft:cyanprintip_professional:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.10.1030"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cyan_soft:cyanprintip_standard:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.10.940"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cyan_soft:cyanprintip_workstation:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.10.836"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cyan_soft:opium4_opi_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.10.1028"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T20:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0757",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mercuryboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "mercuryboard_message_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forum.aria-security.net/showthread.php?t=522",
          "name" : "http://forum.aria-security.net/showthread.php?t=522",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28899",
          "name" : "28899",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487913/100/0/threaded",
          "name" : "20080210 Mercury v1.1.5 Send Message Cross-Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27730",
          "name" : "27730",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019371",
          "name" : "1019371",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in MercuryBoard 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter (aka the message text area), which leads to an injection in the messenger during private message (PM) preview. NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mercuryboard:mercuryboard_message_board:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-13T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0758",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "group_logic",
            "product" : {
              "product_data" : [ {
                "product_name" : "extremez-ip_file_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.2",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "extremez-ip_print_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/ezipirla-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/ezipirla-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://aluigi.org/poc/ezipirla.zip",
          "name" : "http://aluigi.org/poc/ezipirla.zip",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28862",
          "name" : "28862",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.grouplogic.com/files/ez/hot/hotFix51.cfm",
          "name" : "http://www.grouplogic.com/files/ez/hot/hotFix51.cfm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487952/100/0/threaded",
          "name" : "20080211 Multiple vulnerabilities in EztremeZ-IP File and Printer Server 5.1.2x15",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27718",
          "name" : "27718",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0485",
          "name" : "ADV-2008-0485",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in the Zidget/HTTP embedded HTTP server in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allow remote attackers to read arbitrary (1) gif, (2) png, (3) jpg, (4) xml, (5) ico, (6) zip, and (7) html files via a \"..\\\" (dot dot backslash) sequence in the filename."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:group_logic:extremez-ip_file_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:group_logic:extremez-ip_print_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0759",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "group_logic",
            "product" : {
              "product_data" : [ {
                "product_name" : "extremez-ip_file_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.2",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "extremez-ip_print_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-310"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/ezipirla-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/ezipirla-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://aluigi.org/poc/ezipirla.zip",
          "name" : "http://aluigi.org/poc/ezipirla.zip",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28862",
          "name" : "28862",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.grouplogic.com/files/ez/hot/hotFix51.cfm",
          "name" : "http://www.grouplogic.com/files/ez/hot/hotFix51.cfm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487952/100/0/threaded",
          "name" : "20080211 Multiple vulnerabilities in EztremeZ-IP File and Printer Server 5.1.2x15",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27718",
          "name" : "27718",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0485",
          "name" : "ADV-2008-0485",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allows remote attackers to cause a denial of service (daemon crash) via an invalid UAM field in a request to the Apple Filing Protocol (AFP) service on TCP port 548."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:group_logic:extremez-ip_file_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:group_logic:extremez-ip_print_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0760",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "safenet",
            "product" : {
              "product_data" : [ {
                "product_name" : "sentinel_keys_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.4.0",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "sentinel_protection_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/sentinella-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/sentinella-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28863",
          "name" : "28863",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3646",
          "name" : "3646",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487954/100/0/threaded",
          "name" : "20080211 Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27735",
          "name" : "27735",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0499",
          "name" : "ADV-2008-0499",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remote attackers to read arbitrary files via a ..\\ (dot dot backslash) in the URI.  NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-6483."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:safenet:sentinel_keys_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.4.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:safenet:sentinel_protection_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.4.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0761",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_pcchess",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27761",
          "name" : "27761",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40436",
          "name" : "pcchessclub-index-sql-injection(40436)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5104",
          "name" : "5104",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Prince Clan Chess Club (com_pcchess) 0.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a players action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_pcchess:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.8"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T21:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0762",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_iomezun",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/487989/100/0/threaded",
          "name" : "20080212 joomla (k12.tr)(com_iomezun)SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27748",
          "name" : "27748",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40447",
          "name" : "iomezun-index-sql-injection(40447)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the com_iomezun component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_iomezun:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0763",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "larson_software_technology",
            "product" : {
              "product_data" : [ {
                "product_name" : "network_print_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.4.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/lstnpsx-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/lstnpsx-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28890",
          "name" : "28890",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487956/100/0/threaded",
          "name" : "20080211 Format string and buffer-overflow in Lst Network Print Server 9.4.2 build 105",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27732",
          "name" : "27732",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0500",
          "name" : "ADV-2008-0500",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40421",
          "name" : "networkprintserver-npspcsvr-bo(40421)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in NPSpcSVR.exe in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier allows remote attackers to execute arbitrary code via a long argument in a LICENSE command on TCP port 3114."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:larson_software_technology:network_print_server:*:build_105:*:*:*:*:*:*",
          "versionEndIncluding" : "9.4.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0764",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "larson_software_technology",
            "product" : {
              "product_data" : [ {
                "product_name" : "network_print_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.4.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/lstnpsx-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/lstnpsx-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28890",
          "name" : "28890",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487956/100/0/threaded",
          "name" : "20080211 Format string and buffer-overflow in Lst Network Print Server 9.4.2 build 105",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27732",
          "name" : "27732",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0500",
          "name" : "ADV-2008-0500",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40420",
          "name" : "networkprintserver-logging-format-string(40420)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the logging function in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier for Windows might allow remote attackers to execute arbitrary code via format string specifiers in a USEP command on TCP port 3114."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:larson_software_technology:network_print_server:*:build_105:*:*:*:*:*:*",
          "versionEndIncluding" : "9.4.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0765",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "artmedic_webdesign",
            "product" : {
              "product_data" : [ {
                "product_name" : "artmedic_weblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2008-02/0152.html",
          "name" : "20080212 artmedic weblog multiple xss vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28927",
          "name" : "28927",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488223/100/0/threaded",
          "name" : "20080215 artmedic_weblog Cross Site Scriptting Vulnerbility",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488262/100/0/threaded",
          "name" : "20080215 Re: artmedic_weblog Cross Site Scriptting Vulnerbility",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27745",
          "name" : "27745",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in artmedic webdesign weblog allow remote attackers to inject arbitrary web script or HTML via the (1) date parameter to artmedic_print.php and the (2) jahrneu parameter to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:artmedic_webdesign:artmedic_weblog:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-13T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0766",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "brooks_internet_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "rpm_remote_print_manager_elite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.1.11",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "rpm_remote_print_manager_select",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.1.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/rpmlpdbof-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/rpmlpdbof-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28905",
          "name" : "28905",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488010/100/0/threaded",
          "name" : "20080212 Unicode buffer-overflow in RPM Remote Print Manager 4.5.1.11",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27742",
          "name" : "27742",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0501",
          "name" : "ADV-2008-0501",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40432",
          "name" : "rpm-receivedatafile-bo(40432)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in RpmSrvc.exe in Brooks Remote Print Manager (RPM) 4.5.1.11 and earlier (Elite and Select) for Windows allows remote attackers to execute arbitrary code via a long filename in a \"Receive data file\" LPD command.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:brooks_internet_software:rpm_remote_print_manager_elite:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "4.5.1.11"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:brooks_internet_software:rpm_remote_print_manager_select:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "4.5.1.11"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0767",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "extremez",
            "product" : {
              "product_data" : [ {
                "product_name" : "print_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "extremez-ip",
            "product" : {
              "product_data" : [ {
                "product_name" : "file_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/ezipirla-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/ezipirla-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://aluigi.org/poc/ezipirla.zip",
          "name" : "http://aluigi.org/poc/ezipirla.zip",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28862",
          "name" : "28862",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.grouplogic.com/files/ez/hot/hotFix51.cfm",
          "name" : "http://www.grouplogic.com/files/ez/hot/hotFix51.cfm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487952/100/0/threaded",
          "name" : "20080211 Multiple vulnerabilities in EztremeZ-IP File and Printer Server 5.1.2x15",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27718",
          "name" : "27718",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0485",
          "name" : "ADV-2008-0485",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain \"number of URLs\" field is consistent with the packet length, which allows remote attackers to cause a denial of service (daemon crash) via a large integer in this field in a packet to the Service Location Protocol (SLP) service on UDP port 427, triggering an out-of-bounds read."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:extremez:print_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:extremez-ip:file_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T21:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0768",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "informix_dynamic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.tc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.00.tc3tl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.xc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.xc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.00.xc4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.00.xc5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.00.xc6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.00.xc7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.00.xc8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.10.tb4tl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.10.xc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.10.xc2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "informix_storage_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28689",
          "name" : "28689",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27485",
          "name" : "27485",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019281",
          "name" : "1019281",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0317",
          "name" : "ADV-2008-0317",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21294211",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21294211",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=only",
          "name" : "IC55040",
          "refsource" : "AIXAPAR",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=only",
          "name" : "IC55041",
          "refsource" : "AIXAPAR",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40018",
          "name" : "ibm-ids-xdr-bo(40018)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary code via crafted XDR requests."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:*:*:*:*:*:*:*:*",
            "versionStartIncluding" : "10.0",
            "versionEndIncluding" : "10.00.xc8"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:*:*:*:*:*:*:*:*",
            "versionStartIncluding" : "11.10",
            "versionEndIncluding" : "11.10.xc2"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:informix_storage_manager:-:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-13T22:00Z",
    "lastModifiedDate" : "2019-08-01T12:12Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0769",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "opentext",
            "product" : {
              "product_data" : [ {
                "product_name" : "livelink_ecm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059985.html",
          "name" : "20080131 Livelink UTF-7 XSS Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28723",
          "name" : "28723",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://withdk.com/archives/livelink-utf7-xss-advisory.pdf",
          "name" : "http://withdk.com/archives/livelink-utf7-xss-advisory.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27537",
          "name" : "27537",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40123",
          "name" : "livelink-utf7-security-bypass(40123)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Livelink ECM 9.0.0 through 9.7.0 and possibly earlier does not set the charset, which allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded input."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opentext:livelink_ecm:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opentext:livelink_ecm:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opentext:livelink_ecm:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opentext:livelink_ecm:9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opentext:livelink_ecm:9.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opentext:livelink_ecm:9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opentext:livelink_ecm:9.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opentext:livelink_ecm:9.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-14T00:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0770",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibproarcade",
            "product" : {
              "product_data" : [ {
                "product_name" : "ibproarcade",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.vupen.com/english/advisories/2008/0366",
          "name" : "ADV-2008-0366",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5018",
          "name" : "5018",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in arcade.php in ibProArcade 3.3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the g_display_order cookie parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibproarcade:ibproarcade:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.3.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-14T00:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0771",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "site2nite",
            "product" : {
              "product_data" : [ {
                "product_name" : "real_estate_web",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28531",
          "name" : "28531",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3650",
          "name" : "3650",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486414/100/200/threaded",
          "name" : "20080116 [Aria-Security.Net] Real Estate Web SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27330",
          "name" : "27330",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39734",
          "name" : "realestatewebsite-default-sql-injection(39734)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in default.asp in Site2Nite allow remote attackers to execute arbitrary SQL commands via the (1) txtUserName and (2) txtPassword parameters.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:site2nite:real_estate_web:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-14T00:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0772",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_doc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_doc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27679",
          "name" : "27679",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5080",
          "name" : "5080",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the sid parameter in a view task."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_doc:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_doc:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-14T00:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0773",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_comments",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.8.5g",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_comments",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.8.5g",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "phil_taylor",
            "product" : {
              "product_data" : [ {
                "product_name" : "comments",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.8.5g",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "review_script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.8.5g",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27731",
          "name" : "27731",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5094",
          "name" : "5094",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Phil Taylor Comments (com_comments, aka Review Script) 0.5.8.5g and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_comments:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.5.8.5g"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_comments:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.5.8.5g"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phil_taylor:comments:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.5.8.5g"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phil_taylor:review_script:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.5.8.5g"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-14T00:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0774",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "loris",
            "product" : {
              "product_data" : [ {
                "product_name" : "hotel_reservation_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.01",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28881",
          "name" : "28881",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27729",
          "name" : "27729",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search.cgi in Loris Hotel Reservation System 3.01 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the hotel_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:loris:hotel_reservation_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.01"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-14T00:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0775",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "simple_machines",
            "product" : {
              "product_data" : [ {
                "product_name" : "smf_shoutbox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.16b",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28900",
          "name" : "28900",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3651",
          "name" : "3651",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487912/100/0/threaded",
          "name" : "20080210 Simple Machines Forum \"SMF Shoutbox\" Mod Persistent XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489964/100/0/threaded",
          "name" : "20080321 Re: Simple Machines Forum \"SMF Shoutbox\" Mod Persistent XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/491357/100/0/threaded",
          "name" : "20080422 Re: Simple Machines Forum \"SMF Shoutbox\" Mod Persistent XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27727",
          "name" : "27727",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in sboxDB.php in Simple Machines Forum (SMF) Shoutbox 1.14 through 1.16b allows remote attackers to inject arbitrary web script or HTML via strings to the shoutbox form that start with \"&#\", contain the desired script, and end with \";\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:simple_machines:smf_shoutbox:1.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:simple_machines:smf_shoutbox:1.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:simple_machines:smf_shoutbox:1.16b:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-14T00:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0776",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "itechscripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "itechbids",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28887",
          "name" : "28887",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27717",
          "name" : "27717",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5096",
          "name" : "5096",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL commands via the item_id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:itechscripts:itechbids:6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-14T00:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0777",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28928",
          "name" : "28928",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.freebsd.org/advisories/FreeBSD-SA-08:03.sendfile.asc",
          "name" : "FreeBSD-SA-08:03",
          "refsource" : "FREEBSD",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://securitytracker.com/id?1019416",
          "name" : "1019416",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27789",
          "name" : "27789",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access flags of the file descriptor used for sending a file, which allows local users to read the contents of write-only files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T02:00Z",
    "lastModifiedDate" : "2008-09-05T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0778",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3652",
          "name" : "3652",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488045/100/0/threaded",
          "name" : "20080212 QuickTime <= 7.4.1 QTPlugin.ocx Multiple Remote Stack Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27769",
          "name" : "27769",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40475",
          "name" : "apple-quicktime-qtplugin-bo(40475)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5110",
          "name" : "5110",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the (1) SetBgColor, (2) SetHREF, (3) SetMovieName, (4) SetTarget, and (5) SetMatrix methods."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.4.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-14T12:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0779",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fortinet",
            "product" : {
              "product_data" : [ {
                "product_name" : "forticlient_host_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kc.forticare.com/default.asp?id=3618",
          "name" : "http://kc.forticare.com/default.asp?id=3618",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28975",
          "name" : "28975",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3660",
          "name" : "3660",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.reversemode.com/index.php?option=com_mamblog&Itemid=15&task=show&action=view&id=47&Itemid=15",
          "name" : "http://www.reversemode.com/index.php?option=com_mamblog&Itemid=15&task=show&action=view&id=47&Itemid=15",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488071/100/0/threaded",
          "name" : "20080213 [Reversemode Advisory] February Advisories : Microsoft Word 2003 + Fortinet Forticlient",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27776",
          "name" : "27776",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019415",
          "name" : "1019415",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0541/references",
          "name" : "ADV-2008-0541",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40512",
          "name" : "forticlient-fortimon-privilege-escalation(40512)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The fortimon.sys device driver in Fortinet FortiClient Host Security 3.0 MR5 Patch 3 and earlier does not properly initialize its DeviceExtension, which allows local users to access kernel memory and execute arbitrary code via a crafted request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:fortinet:forticlient_host_security:*:mr5_patch_3:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-14T12:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0780",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "moinmoin",
            "product" : {
              "product_data" : [ {
                "product_name" : "moinmoin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://hg.moinmo.in/moin/1.5/rev/2f952fa361c7",
          "name" : "http://hg.moinmo.in/moin/1.5/rev/2f952fa361c7",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://hg.moinmo.in/moin/1.6/rev/9f4bdc7ef80d",
          "name" : "http://hg.moinmo.in/moin/1.6/rev/9f4bdc7ef80d",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28987",
          "name" : "28987",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29010",
          "name" : "29010",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29262",
          "name" : "29262",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29444",
          "name" : "29444",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/33755",
          "name" : "33755",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1514",
          "name" : "DSA-1514",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200803-27.xml",
          "name" : "GLSA-200803-27",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27904",
          "name" : "27904",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0569/references",
          "name" : "ADV-2008-0569",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=432747",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=432747",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/716-1/",
          "name" : "USN-716-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00726.html",
          "name" : "FEDORA-2008-1880",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00752.html",
          "name" : "FEDORA-2008-1905",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in MoinMoin 1.5.x through 1.5.8 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the login action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.3_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.3_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.5_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.5a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-14T21:00Z",
    "lastModifiedDate" : "2018-10-03T21:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0781",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "moinmoin",
            "product" : {
              "product_data" : [ {
                "product_name" : "moinmoin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://hg.moinmo.in/moin/1.5/rev/db212dfc58ef",
          "name" : "http://hg.moinmo.in/moin/1.5/rev/db212dfc58ef",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28987",
          "name" : "28987",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29010",
          "name" : "29010",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29262",
          "name" : "29262",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29444",
          "name" : "29444",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/33755",
          "name" : "33755",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1514",
          "name" : "DSA-1514",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200803-27.xml",
          "name" : "GLSA-200803-27",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27904",
          "name" : "27904",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0569/references",
          "name" : "ADV-2008-0569",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=432748",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=432748",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/716-1/",
          "name" : "USN-716-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00726.html",
          "name" : "FEDORA-2008-1880",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00752.html",
          "name" : "FEDORA-2008-1905",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.5.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) message, (2) pagename, and (3) target filenames."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.3_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.3_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.5_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.5a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-14T21:00Z",
    "lastModifiedDate" : "2018-10-03T21:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0782",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "moinmoin",
            "product" : {
              "product_data" : [ {
                "product_name" : "moinmoin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://hg.moinmo.in/moin/1.5/rev/e69a16b6e630",
          "name" : "http://hg.moinmo.in/moin/1.5/rev/e69a16b6e630",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29010",
          "name" : "29010",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29262",
          "name" : "29262",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29444",
          "name" : "29444",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/33755",
          "name" : "33755",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2008-January/001890.html",
          "name" : "20080124 MoinMoin 1.5.x MOIND_ID cookie Bug Remote Exploit",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1514",
          "name" : "DSA-1514",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200803-27.xml",
          "name" : "GLSA-200803-27",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27404",
          "name" : "27404",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0569/references",
          "name" : "ADV-2008-0569",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39837",
          "name" : "moinmoin-readme-file-overwrite(39837)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/716-1/",
          "name" : "USN-716-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4957",
          "name" : "4957",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the MOIN_ID user ID in a cookie for a userform action.  NOTE: this issue can be leveraged for PHP code execution via the quicklinks parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.3_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.3_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.5_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.5a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-14T21:00Z",
    "lastModifiedDate" : "2018-10-03T21:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0783",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cacti",
            "product" : {
              "product_data" : [ {
                "product_name" : "cacti",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.3a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.5a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6j",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.7a",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.cacti.net/view.php?id=1245",
          "name" : "http://bugs.cacti.net/view.php?id=1245",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html",
          "name" : "SUSE-SR:2008:005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28872",
          "name" : "28872",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28976",
          "name" : "28976",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29242",
          "name" : "29242",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29274",
          "name" : "29274",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30045",
          "name" : "30045",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-18.xml",
          "name" : "GLSA-200803-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3657",
          "name" : "3657",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.cacti.net/release_notes_0_8_7b.php",
          "name" : "http://www.cacti.net/release_notes_0_8_7b.php",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1569",
          "name" : "DSA-1569",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:052",
          "name" : "MDVSA-2008:052",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488013/100/0/threaded",
          "name" : "20080212 cacti -- Multiple security vulnerabilities have been discovered",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488018/100/0/threaded",
          "name" : "20080212 Cacti 0.8.7a Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27749",
          "name" : "27749",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/34991",
          "name" : "34991",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019414",
          "name" : "1019414",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0540",
          "name" : "ADV-2008-0540",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=432758",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=432758",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/50575",
          "name" : "cacti-datainput-xss(50575)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00570.html",
          "name" : "FEDORA-2008-1699",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00593.html",
          "name" : "FEDORA-2008-1737",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary web script or HTML via (1) the view_type parameter to graph.php; (2) the filter parameter to graph_view.php; (3) the action parameter to the draw_navigation_text function in lib/functions.php, reachable through index.php (aka the login page) or data_input.php; or (4) the login_username parameter to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.3a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.5a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6j:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.7a:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-14T23:00Z",
    "lastModifiedDate" : "2018-10-15T22:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0784",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cacti",
            "product" : {
              "product_data" : [ {
                "product_name" : "cacti",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.3a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.5a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6j",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.7a",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html",
          "name" : "SUSE-SR:2008:005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28872",
          "name" : "28872",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28976",
          "name" : "28976",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29242",
          "name" : "29242",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29274",
          "name" : "29274",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-18.xml",
          "name" : "GLSA-200803-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3657",
          "name" : "3657",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.cacti.net/release_notes_0_8_7b.php",
          "name" : "http://www.cacti.net/release_notes_0_8_7b.php",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:052",
          "name" : "MDVSA-2008:052",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488013/100/0/threaded",
          "name" : "20080212 cacti -- Multiple security vulnerabilities have been discovered",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488018/100/0/threaded",
          "name" : "20080212 Cacti 0.8.7a Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27749",
          "name" : "27749",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019414",
          "name" : "1019414",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0540",
          "name" : "ADV-2008-0540",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=432758",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=432758",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00570.html",
          "name" : "FEDORA-2008-1699",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00593.html",
          "name" : "FEDORA-2008-1737",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id parameter and other unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.3a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.5a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6j:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.7a:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-14T23:00Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0785",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cacti",
            "product" : {
              "product_data" : [ {
                "product_name" : "cacti",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.3a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.5a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6j",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.7a",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html",
          "name" : "SUSE-SR:2008:005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28872",
          "name" : "28872",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28976",
          "name" : "28976",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29242",
          "name" : "29242",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29274",
          "name" : "29274",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30045",
          "name" : "30045",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-18.xml",
          "name" : "GLSA-200803-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3657",
          "name" : "3657",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.cacti.net/release_notes_0_8_7b.php",
          "name" : "http://www.cacti.net/release_notes_0_8_7b.php",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1569",
          "name" : "DSA-1569",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:052",
          "name" : "MDVSA-2008:052",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488013/100/0/threaded",
          "name" : "20080212 cacti -- Multiple security vulnerabilities have been discovered",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488018/100/0/threaded",
          "name" : "20080212 Cacti 0.8.7a Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27749",
          "name" : "27749",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019414",
          "name" : "1019414",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0540",
          "name" : "ADV-2008-0540",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=432758",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=432758",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00570.html",
          "name" : "FEDORA-2008-1699",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00593.html",
          "name" : "FEDORA-2008-1737",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated users to execute arbitrary SQL commands via the (1) graph_list parameter to graph_view.php, (2) leaf_id and id parameters to tree.php, (3) local_graph_id parameter to graph_xport.php, and (4) login_username parameter to index.php/login."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.3a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.5a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6j:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.7a:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-14T23:00Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0786",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cacti",
            "product" : {
              "product_data" : [ {
                "product_name" : "cacti",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.3a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.5a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6j",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.7a",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html",
          "name" : "SUSE-SR:2008:005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28872",
          "name" : "28872",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28976",
          "name" : "28976",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29242",
          "name" : "29242",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29274",
          "name" : "29274",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-18.xml",
          "name" : "GLSA-200803-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3657",
          "name" : "3657",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.cacti.net/release_notes_0_8_7b.php",
          "name" : "http://www.cacti.net/release_notes_0_8_7b.php",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:052",
          "name" : "MDVSA-2008:052",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488013/100/0/threaded",
          "name" : "20080212 cacti -- Multiple security vulnerabilities have been discovered",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488018/100/0/threaded",
          "name" : "20080212 Cacti 0.8.7a Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27749",
          "name" : "27749",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019414",
          "name" : "1019414",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0540",
          "name" : "ADV-2008-0540",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=432758",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=432758",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00570.html",
          "name" : "FEDORA-2008-1699",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00593.html",
          "name" : "FEDORA-2008-1737",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CRLF injection vulnerability in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k, when running on older PHP interpreters, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.3a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.5a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.6j:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cacti:cacti:0.8.7a:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-14T23:00Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0787",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybulletinboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybulletinboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_pr2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "rc4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://community.mybboard.net/showthread.php?tid=27675",
          "name" : "http://community.mybboard.net/showthread.php?tid=27675",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28572/",
          "name" : "28572",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486763/100/200/threaded",
          "name" : "20080121 [waraxe-2008-SA#064] - Sql Injection in MyBB 1.2.11",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27378",
          "name" : "27378",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019257",
          "name" : "1019257",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0238",
          "name" : "ADV-2008-0238",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.waraxe.us/advisory-64.html",
          "name" : "http://www.waraxe.us/advisory-64.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5070",
          "name" : "5070",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_pr2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.2.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.2.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:rc4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T01:00Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0788",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://community.mybboard.net/showthread.php?tid=27675",
          "name" : "http://community.mybboard.net/showthread.php?tid=27675",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28572/",
          "name" : "28572",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3656",
          "name" : "3656",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486663",
          "name" : "20080118 MyBB 1.2.11 Multiple XSRF Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0238",
          "name" : "ADV-2008-0238",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site request forgery (CSRF) vulnerabilities in MyBB 1.2.11 and earlier allow remote attackers to (1) hijack the authentication of moderators or administrators for requests that delete threads via a do_multideletethreads action to moderation.php and (2) hijack the authentication of arbitrary users for requests that delete private messages (PM) via a delete action to private.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-15T01:00Z",
    "lastModifiedDate" : "2009-08-20T04:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0789",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "li-scripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "li-countdown",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3655",
          "name" : "3655",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488017/100/0/threaded",
          "name" : "20080212 LI-countdown SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27753",
          "name" : "27753",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in countdown.php in LI-Scripts LI-Countdown allows remote attackers to execute arbitrary SQL commands via the years parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:li-scripts:li-countdown:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0790",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "intermate",
            "product" : {
              "product_data" : [ {
                "product_name" : "winipds",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3revg52-33-021",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/winipds-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/winipds-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28934",
          "name" : "28934",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3658",
          "name" : "3658",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488015/100/0/threaded",
          "name" : "20080212 Directory traversal and DoS in WinIPDS G52-33-021",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489499/100/0/threaded",
          "name" : "20080313 Re: Directory traversal and DoS in WinIPDS G52-33-021",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27757",
          "name" : "27757",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in ipdsserver.exe in Intermate WinIPDS 3.3 G52-33-021 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:intermate:winipds:3.3revg52-33-021:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0791",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "intermate",
            "product" : {
              "product_data" : [ {
                "product_name" : "winipds",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3revg52-33-021",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/winipds-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/winipds-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28934",
          "name" : "28934",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3658",
          "name" : "3658",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488015/100/0/threaded",
          "name" : "20080212 Directory traversal and DoS in WinIPDS G52-33-021",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489499/100/0/threaded",
          "name" : "20080313 Re: Directory traversal and DoS in WinIPDS G52-33-021",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27757",
          "name" : "27757",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ipdsserver.exe in Intermate WinIPDS 3.3 G52-33-021 allows remote attackers to cause a denial of service (CPU consumption) via short packets on TCP port 5001 with the 3, 5, 7, 13, 14, or 15 packet types."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:intermate:winipds:3.3revg52-33-021:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0792",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "f-secure",
            "product" : {
              "product_data" : [ {
                "product_name" : "f-secure_anti-virus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2008",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "f-secure_anti-virus_client_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "f-secure_anti-virus_for_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.65",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "f-secure_anti-virus_for_workstations",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "f-secure_anti-virus_linux_client_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.53",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "f-secure_internet_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2008",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "f-secure_protection_service_for_business",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.00",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "f-secure_protection_service_for_consumers",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.00",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28919",
          "name" : "28919",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.f-secure.com/security/fsc-2008-1.shtml",
          "name" : "http://www.f-secure.com/security/fsc-2008-1.shtml",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019405",
          "name" : "1019405",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019412",
          "name" : "1019412",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019413",
          "name" : "1019413",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0544/references",
          "name" : "ADV-2008-0544",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40480",
          "name" : "fsecure-cab-rar-security-bypass(40480)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted CAB archive."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:2007:second_edition:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:2008:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_client_security:6.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_client_security:6.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_client_security:7.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_client_security:7.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_for_linux:4.65:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_for_workstations:5.44:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_for_workstations:7.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_for_workstations:7.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_linux_client_security:5.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_linux_client_security:5.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_internet_security:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_internet_security:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_internet_security:2007:second_edition:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_internet_security:2008:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_protection_service_for_business:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.00"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_protection_service_for_consumers:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.00"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T02:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0793",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tendenci",
            "product" : {
              "product_data" : [ {
                "product_name" : "cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blog.tendenci.com/2008/02/cross-site-scri.html",
          "name" : "http://blog.tendenci.com/2008/02/cross-site-scri.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://holisticinfosec.blogspot.com/2008/02/fastest-fix-in-west-vendors-excellent.html",
          "name" : "http://holisticinfosec.blogspot.com/2008/02/fastest-fix-in-west-vendors-excellent.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28882",
          "name" : "28882",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27782",
          "name" : "27782",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40477",
          "name" : "tendencicms-search-xss(40477)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in search.asp in Tendenci CMS allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) searchtext, (3) jobcategoryid, (4) contactcompany, and unspecified other parameters.  NOTE: some of these details are obtained from third party information.  NOTE: it is not clear whether this affects Tendenci Enterprise Edition in addition to the product's deployment on Tendenci's own server farm. If only the latter was affected, then this issue should not be included in CVE."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tendenci:cms:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-15T02:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0794",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "affiliate_market",
            "product" : {
              "product_data" : [ {
                "product_name" : "affiliate_market",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27777",
          "name" : "27777",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40472",
          "name" : "affiliatemarket-header-file-include(40472)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5108",
          "name" : "5108",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in user/header.php in Affiliate Market 0.1 BETA allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:affiliate_market:affiliate_market:0.1_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0795",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "joomla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "mambo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mgfi",
            "product" : {
              "product_data" : [ {
                "product_name" : "xfaq",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27784",
          "name" : "27784",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40494",
          "name" : "xfaq-index-sql-injection(40494)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5109",
          "name" : "5109",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mgfi:xfaq:1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0796",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nuboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "nuboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://www.exploit-db.com/exploits/5115",
          "name" : "5115",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in threads.php in Nuboard 0.5 allows remote attackers to execute arbitrary SQL commands via the ssid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nuboard:nuboard:0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0797",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "itheora",
            "product" : {
              "product_data" : [ {
                "product_name" : "itheora",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://en.wikipedia.org/wiki/Talk:Itheora",
          "name" : "http://en.wikipedia.org/wiki/Talk:Itheora",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://menguy.aymeric.free.fr/theora/news.php",
          "name" : "http://menguy.aymeric.free.fr/theora/news.php",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28929",
          "name" : "28929",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27788",
          "name" : "27788",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40506",
          "name" : "itheora-download-directory-traversal(40506)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in lib/download.php in iTheora 1.0 rc1 allows remote attackers to read arbitrary files via directory traversal sequences in the url parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:itheora:itheora:1.0:rc1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T22:00Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0798",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "artmedic_webdesign",
            "product" : {
              "product_data" : [ {
                "product_name" : "artmedic_weblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28927",
          "name" : "28927",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488115/100/100/threaded",
          "name" : "20080213 artmedic weblog multiple local file inclusion vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27797",
          "name" : "27797",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40522",
          "name" : "artmedicweblog-artmedicprint-file-include(40522)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5116",
          "name" : "5116",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in artmedic webdesign weblog 1.0, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ta parameter to artmedic_index.php, reached through index.php; and the (2) date parameter to artmedic_print.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:artmedic_webdesign:artmedic_weblog:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T22:00Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0799",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_quiz",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.81",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_quiz",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.81",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28980",
          "name" : "28980",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27808",
          "name" : "27808",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5119",
          "name" : "5119",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_quiz:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.81"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_quiz:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.81"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0800",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_mcquiz",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28940",
          "name" : "28940",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27809",
          "name" : "27809",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5118",
          "name" : "5118",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_mcquiz:0.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0801",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "paxxgallery",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_paxxgallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27811",
          "name" : "27811",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40497",
          "name" : "paxxgallery-index-sql-injection(40497)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5117",
          "name" : "5117",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the PAXXGallery (com_paxxgallery) 0.2 component for Mambo and Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the iid parameter in a view action, and possibly (2) the userid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:paxxgallery:com_paxxgallery:0.2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:mambo-foundation:mambo:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0802",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_mediaslide",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mediaslide",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_mediaslide",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28962",
          "name" : "28962",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27805",
          "name" : "27805",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40517",
          "name" : "mediaslide-index-sql-injection(40517)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5120",
          "name" : "5120",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the MediaSlide (com_mediaslide) 0.5 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the albumnum parameter in a contact action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_mediaslide:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediaslide:com_mediaslide:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0803",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lookstrike",
            "product" : {
              "product_data" : [ {
                "product_name" : "lan_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40519",
          "name" : "lookstrikelanmanager-sysconf-file-include(40519)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5121",
          "name" : "5121",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in LookStrike Lan Manager 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the sys_conf[path][real] parameter to (1) modules\\class\\Table.php; (2) db_admins.php, (3) db_alert.php, (4) db_double.php, (5) db_games.php, (6) db_matches.php, (7) db_match_teams.php, (8) db_news.php, (9) db_platform.php, (10) db_players.php, (11) db_server_group.php, (12) db_server_ip.php, (13) db_teams.php, (14) db_team_players.php, (15) db_tournaments.php, (16) db_tournament_teams.php, and (17) db_trees.php in modules\\class\\db\\; and (18) Match.php, (19) MatchTeam.php, (20) Rule.php, (21) RuleBuilder.php, (22) RulePool.php, (23) RuleSingle.php, (24) RuleTree.php, (25) Tournament.php, (26) TournamentTeam.php, (27) Tree.php, and (28) TreeSingle.php in modules\\class\\tournament\\.  NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lookstrike:lan_manager:0.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-15T22:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0804",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "thecus",
            "product" : {
              "product_data" : [ {
                "product_name" : "n5200pro_nas_server_control_panel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29013",
          "name" : "29013",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27865",
          "name" : "27865",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5150",
          "name" : "5150",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to execute arbitrary PHP code via a URL in the name parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:thecus:n5200pro_nas_server_control_panel:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T00:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0805",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "reality",
            "product" : {
              "product_data" : [ {
                "product_name" : "medias_phpizabi",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.848b",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27847",
          "name" : "27847",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0585",
          "name" : "ADV-2008-0585",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5136",
          "name" : "5136",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension from the event page, then accessing it via a direct request to the file in system/cache/pictures."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:reality:medias_phpizabi:0.848b:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T00:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0806",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "paul_pelzl",
            "product" : {
              "product_data" : [ {
                "product_name" : "wyrd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.3b_3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-59"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=466382",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=466382",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/29009",
          "name" : "29009",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29113",
          "name" : "29113",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27848",
          "name" : "27848",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=433719",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=433719",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00825.html",
          "name" : "FEDORA-2008-1963",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00841.html",
          "name" : "FEDORA-2008-1986",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "wyrd 1.4.3b allows local users to overwrite arbitrary files via a symlink attack on the wyrd-tmp.[USERID] temporary file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:paul_pelzl:wyrd:1.4.3b_3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T00:00Z",
    "lastModifiedDate" : "2008-09-05T21:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0807",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "horde",
            "product" : {
              "product_data" : [ {
                "product_name" : "groupware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "groupware_webmail_edition",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "turba_contact_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464058",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464058",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.horde.org/archives/announce/2008/000378.html",
          "name" : "[announce] 20080215 Turba H3 (2.1.7) (final)",
          "refsource" : "MLIST",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.horde.org/archives/announce/2008/000379.html",
          "name" : "[announce] 20080215 Turba H3 (2.2-RC3)",
          "refsource" : "MLIST",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.horde.org/archives/announce/2008/000380.html",
          "name" : "[announce] 20080215 Horde Groupware 1.0.4 (final)",
          "refsource" : "MLIST",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.horde.org/archives/announce/2008/000381.html",
          "name" : "[announce] 20080215 Horde Groupware Webmail Edition 1.0.5 (final)",
          "refsource" : "MLIST",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28982",
          "name" : "28982",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29071",
          "name" : "29071",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29184",
          "name" : "29184",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29185",
          "name" : "29185",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29186",
          "name" : "29186",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1507",
          "name" : "DSA-1507",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27844",
          "name" : "27844",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019433",
          "name" : "1019433",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0593/references",
          "name" : "ADV-2008-0593",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=432027",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=432027",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00888.html",
          "name" : "FEDORA-2008-2040",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00927.html",
          "name" : "FEDORA-2008-2087",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified object_id parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:alpha:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:amd64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:arm:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:hppa:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:ia-32:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:ia-64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:m68k:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:mips:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:mipsel:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:powerpc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:s-390:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:sparc:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:horde:groupware:1.0.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:horde:groupware_webmail_edition:1.0.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:horde:turba_contact_manager:2.1.6:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T01:00Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0808",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ikiwiki",
            "product" : {
              "product_data" : [ {
                "product_name" : "ikiwiki",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.33.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.46",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "2.31",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=465110",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=465110",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://ikiwiki.info/security/#index30h2",
          "name" : "http://ikiwiki.info/security/#index30h2",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28911",
          "name" : "28911",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29369",
          "name" : "29369",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1523",
          "name" : "DSA-1523",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27760",
          "name" : "27760",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the meta plugin in Ikiwiki before 1.1.47 allows remote attackers to inject arbitrary web script or HTML via meta tags."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:1.33.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.46"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:2.31:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-19T01:00Z",
    "lastModifiedDate" : "2008-09-05T21:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0809",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ikiwiki",
            "product" : {
              "product_data" : [ {
                "product_name" : "ikiwiki",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.45",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://ikiwiki.info/security/#index27h2",
          "name" : "http://ikiwiki.info/security/#index27h2",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28911",
          "name" : "28911",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29369",
          "name" : "29369",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1523",
          "name" : "DSA-1523",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27760",
          "name" : "27760",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the htmlscrubber in Ikiwiki before 1.1.46 allows remote attackers to inject arbitrary web script or HTML via title contents."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ikiwiki:ikiwiki:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.45"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-19T01:00Z",
    "lastModifiedDate" : "2008-09-05T21:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0810",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_scheduling_component",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_scheduling_component",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3662",
          "name" : "3662",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488269/100/0/threaded",
          "name" : "20080216 joomla SQL Injection( com_scheduling)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27830",
          "name" : "27830",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the com_scheduling module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_scheduling_component:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_scheduling_component:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0811",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "auracms",
            "product" : {
              "product_data" : [ {
                "product_name" : "auracms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.62",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27841",
          "name" : "27841",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019430",
          "name" : "1019430",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5130",
          "name" : "5130",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote attackers to execute arbitrary SQL commands via (1) the kid parameter to (a) mod/dl.php or (b) mod/links.php, and (2) the query parameter to search.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:auracms:auracms:1.62:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0812",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "banpro",
            "product" : {
              "product_data" : [ {
                "product_name" : "net_banpro_dms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28992",
          "name" : "28992",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3666",
          "name" : "3666",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488271/100/0/threaded",
          "name" : "20080216 banpro-dms 1.0 local file inclusion vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27831",
          "name" : "27831",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in DMS/index.php in BanPro DMS 1.0 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the action parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:banpro:net_banpro_dms:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0813",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xpweb",
            "product" : {
              "product_data" : [ {
                "product_name" : "xpweb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29006",
          "name" : "29006",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27838",
          "name" : "27838",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0584",
          "name" : "ADV-2008-0584",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5137",
          "name" : "5137",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in Download.php in XPWeb 3.0.1, 3.3.2, and possibly other versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xpweb:xpweb:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xpweb:xpweb:3.3.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0814",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "truc",
            "product" : {
              "product_data" : [ {
                "product_name" : "truc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27839",
          "name" : "27839",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5129",
          "name" : "5129",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in download.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the upload_filename parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:truc:truc:0.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T02:00Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0815",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "egitimhost",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_mezun",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_mezun",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3663",
          "name" : "3663",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487992/100/100/threaded",
          "name" : "20080212 joomll(k12.tr)(com_mezun)SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27755",
          "name" : "27755",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40448",
          "name" : "mezun-index-sql-injection(40448)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the com_mezun component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:egitimhost:com_mezun:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_mezun:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0816",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "com_sg",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_sg",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3664",
          "name" : "3664",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488272/100/0/threaded",
          "name" : "20080215 joomla SQL Injection(com_sg)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27821",
          "name" : "27821",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the com_sg component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the pid parameter in an order task."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:com_sg:com_sg:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0817",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_filebase_component",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_filebase_component",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3665",
          "name" : "3665",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488268/100/0/threaded",
          "name" : "20080215 joomla SQL Injection(com_filebase)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488284/100/0/threaded",
          "name" : "20080216 joomla SQL Injection(com_filebase)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27829",
          "name" : "27829",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40616",
          "name" : "filebase-index-sql-injection(40616)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the com_filebase component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_filebase_component:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_filebase_component:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T02:00Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0818",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freephpgallery",
            "product" : {
              "product_data" : [ {
                "product_name" : "freephpgallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28972",
          "name" : "28972",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/forum/forum.php?forum_id=785794",
          "name" : "http://sourceforge.net/forum/forum.php?forum_id=785794",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27806",
          "name" : "27806",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0589",
          "name" : "ADV-2008-0589",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5124",
          "name" : "5124",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in freePHPgallery 0.6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie to (1) comment.php, (2) index.php, and (3) show.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freephpgallery:freephpgallery:0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T20:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0819",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "plutostatus",
            "product" : {
              "product_data" : [ {
                "product_name" : "plutostatus_locator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0pre_alpha",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3667",
          "name" : "3667",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488141/100/0/threaded",
          "name" : "20080214 PlutoStatus Locator v1.0pre (alpha) local file inclusion vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27802",
          "name" : "27802",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter."
        }, {
          "lang" : "en",
          "value" : "The security focus bid link states that this is a local file include vulnerability."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plutostatus:plutostatus_locator:1.0pre_alpha:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T20:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0820",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "etomite",
            "product" : {
              "product_data" : [ {
                "product_name" : "etomite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6.1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28964",
          "name" : "28964",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3669",
          "name" : "3669",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.etomite.com/forums/index.php?showtopic=7647",
          "name" : "http://www.etomite.com/forums/index.php?showtopic=7647",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488122/100/0/threaded",
          "name" : "20080214 etomite xss",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488304/100/100/threaded",
          "name" : "20080218 Re: etomite xss",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27794",
          "name" : "27794",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40525",
          "name" : "etomite-index-xss(40525)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  Cross-site scripting (XSS) vulnerability in index.php in Etomite 0.6.1.4 Final allows remote attackers to inject arbitrary web script or HTML via $_SERVER['PHP_INFO'].  NOTE: the vendor disputes this issue in a followup, stating that the affected variable is $_SERVER['PHP_SELF'], and \"This is not an Etomite specific exploit and I would like the report rescinded.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:etomite:etomite:0.6.1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-19T20:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0821",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "osi_codes_inc.",
            "product" : {
              "product_data" : [ {
                "product_name" : "phplive",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27807",
          "name" : "27807",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5125",
          "name" : "5125",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in admin/traffic/knowledge_searchm.php in OSI Codes Inc. PHP Live! 3.2.2 allows remote attackers to execute arbitrary SQL commands via the questid parameter in an expand_question action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:osi_codes_inc.:phplive:3.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T20:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0822",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "scribe",
            "product" : {
              "product_data" : [ {
                "product_name" : "scribe",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3668",
          "name" : "3668",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488140/100/0/threaded",
          "name" : "20080214 scribe 0.2 local file inclusion vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27803",
          "name" : "27803",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5123",
          "name" : "5123",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in index.php in Scribe 0.2 allows remote attackers to read arbitrary local files via a .. (dot dot) in the page parameter."
        }, {
          "lang" : "en",
          "value" : "Security focus bid link notes that this is a local file include vulnerability."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:scribe:scribe:0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T20:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0823",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "header_image",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.x-1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/221359",
          "name" : "http://drupal.org/node/221359",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/28876",
          "name" : "28876",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27787",
          "name" : "27787",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0571",
          "name" : "ADV-2008-0571",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40510",
          "name" : "drupal-headerimage-security-bypass(40510)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:header_image:5.x-1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T20:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0824",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "caroline",
            "product" : {
              "product_data" : [ {
                "product_name" : "caroline",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.6.0",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.6.3",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.7",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.7.9",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.8",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28942",
          "name" : "28942",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=575934",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=575934",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the php2phps function in Claroline before 1.8.9 has unknown impact and attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.7"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.7.9"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.8"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T20:44Z",
    "lastModifiedDate" : "2008-09-05T21:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0825",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "caroline",
            "product" : {
              "product_data" : [ {
                "product_name" : "caroline",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.6.0",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.6.3",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.7",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.7.9",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.8",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28942",
          "name" : "28942",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=575934",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=575934",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27846",
          "name" : "27846",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0596",
          "name" : "ADV-2008-0596",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Claroline before 1.8.9 allows remote attackers to execute arbitrary SQL commands via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.7"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.7.9"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.8"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T20:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0826",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "caroline",
            "product" : {
              "product_data" : [ {
                "product_name" : "caroline",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.6.0",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.6.3",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.7",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.7.9",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.8",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28942",
          "name" : "28942",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=575934",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=575934",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27846",
          "name" : "27846",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0596",
          "name" : "ADV-2008-0596",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Claroline before 1.8.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.7"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.7.9"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:caroline:caroline:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.8"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-19T20:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0827",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpnuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "book",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27863",
          "name" : "27863",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40857",
          "name" : "books-cid-sql-injection(40857)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5147",
          "name" : "5147",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpnuke:book:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T21:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0828",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "atutor",
            "product" : {
              "product_data" : [ {
                "product_name" : "atutor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29015",
          "name" : "29015",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3670",
          "name" : "3670",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488293/100/0/threaded",
          "name" : "20080217 ATutor <= 1.5.5 Cross Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27855",
          "name" : "27855",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) attributes such as style and onmouseover in (a) forum post or (b) mail; or (2) the website field of the profile."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:0.9.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:0.9.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.5.1:pl1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.5.1:pl2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.5.3:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.5.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.5.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:1.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atutor:atutor:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-19T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0829",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "joomla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "joomlapixel",
            "product" : {
              "product_data" : [ {
                "product_name" : "jooget",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "mambo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forum.joomlaitalia.com/index.php?topic=388.0",
          "name" : "http://forum.joomlaitalia.com/index.php?topic=388.0",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://members.joomlapixel.eu/download/componenti/patch-jooget-2.6.8-sql-injection/details.html",
          "name" : "http://members.joomlapixel.eu/download/componenti/patch-jooget-2.6.8-sql-injection/details.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28998",
          "name" : "28998",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27836",
          "name" : "27836",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5132",
          "name" : "5132",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in jooget.php in the Joomlapixel Jooget! (com_jooget) 2.6.8 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail task."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomlapixel:jooget:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T21:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0830",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "iphoto",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27867",
          "name" : "27867",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019488",
          "name" : "1019488",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5151",
          "name" : "5151",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (crash) via a malformed dpap: URI, a different vulnerability than CVE-2008-0043."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:iphoto:4.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-19T22:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0831",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "rapid_recipe",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://www.exploit-db.com/exploits/5103",
          "name" : "5103",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in the Rapid Recipe (com_rapidrecipe) 1.6.5 and earlier component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) user_id or (2) category_id parameter.  NOTE: this might overlap CVE-2008-0754."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:rapid_recipe:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-20T19:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0832",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "kemas_antonius_com_quran",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "kemas_antonius_com_quran",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2008-02/0399.html",
          "name" : "20080223 php-nuke Quran SQL Injection(surano)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/52226",
          "name" : "52226",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28986",
          "name" : "28986",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27842",
          "name" : "27842",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40573",
          "name" : "quran-index-sql-injection(40573)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5128",
          "name" : "5128",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Kemas Antonius com_quran 1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the surano parameter in a viewayat action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:kemas_antonius_com_quran:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:kemas_antonius_com_quran:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-20T19:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0833",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_galeria",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/488285",
          "name" : "20080216 joomla SQL Injection(com_galeria)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27833",
          "name" : "27833",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5134",
          "name" : "5134",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the com_galeria component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_galeria:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-20T19:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0834",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_quickr",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29004",
          "name" : "29004",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27840",
          "name" : "27840",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019431",
          "name" : "1019431",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0590",
          "name" : "ADV-2008-0590",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg24016411",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg24016411",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Lotus Quickr for i5/OS before 8.0.0.2 Hotfix 11, when anonymous access is disabled on HTTP ports, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_quickr:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_quickr:8.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-20T21:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0835",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "simple_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "simple_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/488288/100/0/threaded",
          "name" : "20080217 Simple CMS <= 1.0.3 (indexen.php area) Remote SQL Injection Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27843",
          "name" : "27843",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5131",
          "name" : "5131",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in indexen.php in Simple CMS 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the area parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:simple_cms:simple_cms:1.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-20T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0836",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28990",
          "name" : "28990",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-200635-1",
          "name" : "200635",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019429",
          "name" : "1019429",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0582",
          "name" : "ADV-2008-0582",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the vuidmice STREAMS modules in Sun Solaris 9 and 10 on x86 architectures allows local users to cause a denial of service (panic) via unspecified vectors that trigger a NULL pointer dereference in the vuid3ps2 module, a different issue than CVE-2007-5319."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10:*:x86:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-20T21:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0837",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "john_godley",
            "product" : {
              "product_data" : [ {
                "product_name" : "search_unleashed",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "search_unleashed_plugin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28968",
          "name" : "28968",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3674",
          "name" : "3674",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://urbangiraffe.com/tracker/issues/show/60",
          "name" : "http://urbangiraffe.com/tracker/issues/show/60",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488109/100/0/threaded",
          "name" : "20080213 Search Unleashed 0.2.10 JavaScript injection (Wordpress plugin)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27791",
          "name" : "27791",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40513",
          "name" : "searchunleashed-log-xss(40513)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the log feature in the John Godley Search Unleashed 0.2.10 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, which is not properly handled when the administrator views the log file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:john_godley:search_unleashed:0.2.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:search_unleashed_plugin:0.2.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-20T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0838",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sophos",
            "product" : {
              "product_data" : [ {
                "product_name" : "es1000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.0.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "es4000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28961",
          "name" : "28961",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3673",
          "name" : "3673",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.infigo.hr/en/in_focus/advisories/INFIGO-2008-02-13",
          "name" : "http://www.infigo.hr/en/in_focus/advisories/INFIGO-2008-02-13",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488206/100/0/threaded",
          "name" : "20080215 [INFIGO-2008-02-13]: SOPHOS Email Security Appliance Cross Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27813",
          "name" : "27813",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019427",
          "name" : "1019427",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.sophos.com/support/knowledgebase/article/34733.html",
          "name" : "http://www.sophos.com/support/knowledgebase/article/34733.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0574",
          "name" : "ADV-2008-0574",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface in Sophos ES1000 and ES4000 Email Security Appliance 2.1.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) error and (2) go parameters to the login page."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sophos:es1000:2.1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sophos:es4000:2.1.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-20T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0839",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "astats",
            "product" : {
              "product_data" : [ {
                "product_name" : "astatspro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_astatspro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29008",
          "name" : "29008",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27850",
          "name" : "27850",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40611",
          "name" : "astatspro-refer-sql-injection(40611)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5138",
          "name" : "5138",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in refer.php in the astatsPRO (com_astatspro) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:astats:astatspro:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_astatspro:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-20T21:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0840",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "publicwarehouse",
            "product" : {
              "product_data" : [ {
                "product_name" : "lightblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29017",
          "name" : "29017",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488283/100/0/threaded",
          "name" : "20080217 lightblog 9.6 local file inclusion vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27837",
          "name" : "27837",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0621",
          "name" : "ADV-2008-0621",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5140",
          "name" : "5140",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in view_member.php in Public Warehouse LightBlog 9.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the username parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:publicwarehouse:lightblog:9.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-20T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0841",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_ricette_component",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_ricette_component",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27834",
          "name" : "27834",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5133",
          "name" : "5133",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Giorgio Nordo Ricette (com_ricette) 1.0 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_ricette_component:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_ricette_component:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-20T21:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0842",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_clasifier",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27917",
          "name" : "27917",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0620",
          "name" : "ADV-2008-0620",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40629",
          "name" : "clasifier-index-sql-injection(40629)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5146",
          "name" : "5146",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Classifier (com_clasifier) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_clasifier:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-20T21:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0843",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "statcountex",
            "product" : {
              "product_data" : [ {
                "product_name" : "statcountex",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.org/1002-exploits/statcountex-disclose.txt",
          "name" : "http://packetstormsecurity.org/1002-exploits/statcountex-disclose.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28984",
          "name" : "28984",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3675",
          "name" : "3675",
          "refsource" : "SREASON",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.exploit-db.com/exploits/11434",
          "name" : "11434",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488200/100/0/threaded",
          "name" : "20080214 StatCounteX 3.0 & 3.1 Admin Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27814",
          "name" : "27814",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a direct request to admin.asp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:statcountex:statcountex:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:statcountex:statcountex:3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-20T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0844",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_pccookbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27864",
          "name" : "27864",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40620",
          "name" : "pccookbook-index-sql-injection(40620)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5145",
          "name" : "5145",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the PccookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_pccookbook:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-20T21:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0845",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "dean_logan_wp-people_plugin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3672",
          "name" : "3672",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488282/100/0/threaded",
          "name" : "20080216 Wordpress Plugin (wp-people) SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27858",
          "name" : "27858",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40860",
          "name" : "wppeople-wppeoplepopup-sql-injection(40860)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in wp-people-popup.php in Dean Logan WP-People plugin 1.6.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the person parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:dean_logan_wp-people_plugin:1.6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-20T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0846",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_profile",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_profile",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120335361520072&w=2",
          "name" : "20080216 joomla SQL Injection(com_profile)",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27851",
          "name" : "27851",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the com_profile component for Joomla! allows remote attackers to execute arbitrary SQL commands via the oid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_profile:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_profile:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-20T21:44Z",
    "lastModifiedDate" : "2008-09-05T21:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0847",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xoops",
            "product" : {
              "product_data" : [ {
                "product_name" : "mytopics",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/488315/100/0/threaded",
          "name" : "20080218 XOOPS Module myTopics-print SQL Injection(articleid)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27861",
          "name" : "27861",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40627",
          "name" : "mytopics-print-sql-injection(40627)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5148",
          "name" : "5148",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary SQL commands via the articleid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xoops:mytopics:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0848",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "crafty_syntax_live_help",
            "product" : {
              "product_data" : [ {
                "product_name" : "crafty_syntax_live_help",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.15",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29201",
          "name" : "29201",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3688",
          "name" : "3688",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=580994",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=580994",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488286/100/0/threaded",
          "name" : "20080218 Crafty Syntax Xss Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489016/100/0/threaded",
          "name" : "20080302 Re: Crafty Syntax Xss Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27859",
          "name" : "27859",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40636",
          "name" : "cslh-lostsheep-xss(40636)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in lostsheep.php in Crafty Syntax Live Help (CSLH) before 2.14.16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: the versions claimed by the original researcher are probably incorrect."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:crafty_syntax_live_help:crafty_syntax_live_help:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.4.15"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-21T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0849",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_downloads",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_downloads",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3676",
          "name" : "3676",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488291/100/0/threaded",
          "name" : "20080216 joomla SQL Injection (cat)(com_downloads)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27860",
          "name" : "27860",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40621",
          "name" : "downloads-indexphp-sql-injection(40621)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat function, a different vector than CVE-2008-0652."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_downloads:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_downloads:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0850",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dokeos",
            "product" : {
              "product_data" : [ {
                "product_name" : "dokeos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://projects.dokeos.com/index.php?do=details&task_id=2218",
          "name" : "http://projects.dokeos.com/index.php?do=details&task_id=2218",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28974",
          "name" : "28974",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3687",
          "name" : "3687",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488314/100/0/threaded",
          "name" : "20080219 [DSECRG-08-015] Multiple Security Vulnerabilities in Dokeos 1.8.4",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27792",
          "name" : "27792",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019425",
          "name" : "1019425",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0587",
          "name" : "ADV-2008-0587",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to whoisonline.php, (2) tracking_list_coaches_column parameter to main/mySpace/index.php, (3) tutor_name parameter to main/create_course/add_course.php, the (4) Referer HTTP header to index.php, and the (5) X-Fowarded-For HTTP header to main/admin/class_list.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dokeos:dokeos:1.8.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0851",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dokeos",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-learning_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://projects.dokeos.com/index.php?do=details&task_id=2218",
          "name" : "http://projects.dokeos.com/index.php?do=details&task_id=2218",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28974",
          "name" : "28974",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3687",
          "name" : "3687",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488314/100/0/threaded",
          "name" : "20080219 [DSECRG-08-015] Multiple Security Vulnerabilities in Dokeos 1.8.4",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27792",
          "name" : "27792",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019425",
          "name" : "1019425",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0587",
          "name" : "ADV-2008-0587",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php, (2) courseCode parameter to main/calendar/myagenda.php, (3) category parameter to main/admin/course_category.php, (4) message parameter to main/admin/session_list.php in a show_message action, and (5) an avatar image to main/auth/profile.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dokeos:e-learning_system:1.8.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-21T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0852",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freesshd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freesshd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/freesshdnull-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/freesshdnull-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29002",
          "name" : "29002",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488363/100/0/threaded",
          "name" : "20080219 NULL pointer crash in freeSSHd 1.20",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27845",
          "name" : "27845",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0591",
          "name" : "ADV-2008-0591",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "freeSSHd 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a SSH2_MSG_NEWKEYS packet to TCP port 22, which triggers a NULL pointer dereference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freesshd:freesshd:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0853",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_detail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_detail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3677",
          "name" : "3677",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488278/100/0/threaded",
          "name" : "20080216 joomla SQL Injection(com_detail)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488325/100/0/threaded",
          "name" : "20080218 joomla SQL Injection(com_detail)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27853",
          "name" : "27853",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the com_detail component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.  NOTE: this issue might be site-specific.  If so, it should not be included in CVE."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_detail:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_detail:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0854",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_salesrep",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_salesrep",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3678",
          "name" : "3678",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488267/100/0/threaded",
          "name" : "20080215 joomla SQL Injection(com_salesrep)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27827",
          "name" : "27827",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40619",
          "name" : "salesrep-index-sql-injection(40619)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the com_salesrep component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the rid parameter in a showrep action to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_salesrep:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_salesrep:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0855",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_facileforms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_facileforms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3679",
          "name" : "3679",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488335/100/0/threaded",
          "name" : "20080218 joomla SQL Injection(com_facileforms)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27880",
          "name" : "27880",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the Facile Forms (com_facileforms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_facileforms:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:com_facileforms:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0856",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "e-vision",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-vision_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27816",
          "name" : "27816",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40859",
          "name" : "evisioncms-iframe-print-sql-injection(40859)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in e-Vision CMS 2.02 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) iframe.php and (2) print.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e-vision:e-vision_cms:2.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0857",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "woltlab",
            "product" : {
              "product_data" : [ {
                "product_name" : "burning_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.3_pl1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29020",
          "name" : "29020",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3680",
          "name" : "3680",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488345/100/0/threaded",
          "name" : "20080219 WoltLab Burning Board 3.0.3 PL1 SQL-Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27885",
          "name" : "27885",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5164",
          "name" : "5164",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrary SQL commands via the sortOrder parameter to the PMList page."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board:3.0.3_pl1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0858",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kerio",
            "product" : {
              "product_data" : [ {
                "product_name" : "kerio_mailserver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.4.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "visnetic",
            "product" : {
              "product_data" : [ {
                "product_name" : "visnetic_antivirus_plug-in_for_mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29021",
          "name" : "29021",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kerio.com/kms_history.html",
          "name" : "http://www.kerio.com/kms_history.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27868",
          "name" : "27868",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019428",
          "name" : "1019428",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0594",
          "name" : "ADV-2008-0594",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the Visnetic anti-virus plugin in Kerio MailServer before 6.5.0 might allow remote attackers to execute arbitrary code via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.4.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:visnetic:visnetic_antivirus_plug-in_for_mail_server:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T00:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0859",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kerio",
            "product" : {
              "product_data" : [ {
                "product_name" : "kerio_mailserver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          }, {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29021",
          "name" : "29021",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kerio.com/kms_history.html",
          "name" : "http://www.kerio.com/kms_history.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27868",
          "name" : "27868",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019428",
          "name" : "1019428",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0594",
          "name" : "ADV-2008-0594",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Kerio MailServer before 6.5.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to decoding of uuencoded input, which triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.7.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.7.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.7.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.7.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:5.7.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:6.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:6.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:6.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:6.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:6.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:6.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:6.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:6.4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T00:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0860",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kerio",
            "product" : {
              "product_data" : [ {
                "product_name" : "avg_plugin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "kerio_mailserver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.4.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29021",
          "name" : "29021",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kerio.com/kms_history.html",
          "name" : "http://www.kerio.com/kms_history.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27868",
          "name" : "27868",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019428",
          "name" : "1019428",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0594",
          "name" : "ADV-2008-0594",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the AVG plugin in Kerio MailServer before 6.5.0 has unspecified impact via unknown remote attack vectors related to null DACLs."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:avg_plugin:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:kerio_mailserver:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.4.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T00:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0861",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_quickplace",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29025",
          "name" : "29025",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securiteam.com/securitynews/5AP0B2KNFM.html",
          "name" : "http://www.securiteam.com/securitynews/5AP0B2KNFM.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27871",
          "name" : "27871",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019432",
          "name" : "1019432",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0841/references",
          "name" : "ADV-2008-0841",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in leg/Main.nsf in IBM Lotus Quickplace 7.0 allows remote attackers to inject arbitrary web script or HTML via an h_SearchString sub-parameter in the PreSetFields parameter of an EditDocument action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_quickplace:7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-21T01:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0862",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_notes",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29031",
          "name" : "29031",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0600/references",
          "name" : "ADV-2008-0600",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg21257250",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg21257250",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email message to another user, which allows user-assisted remote attackers to bypass Execution Control List (ECL) protection."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-21T01:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0863",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/260",
          "name" : "BEA08-187.00",
          "refsource" : "BEA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019455",
          "name" : "1019455",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0612/references",
          "name" : "ADV-2008-0612",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server and WebLogic Express 9.0 and 9.1 exposes the web service's WSDL and security policies, which allows remote attackers to obtain sensitive information and potentially launch further attacks."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:*:express:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T01:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0864",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1_sp6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/256",
          "name" : "BEA08-183.00",
          "refsource" : "BEA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29041",
          "name" : "29041",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019454",
          "name" : "1019454",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0613",
          "name" : "ADV-2008-0613",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Admin Tools in BEA WebLogic Portal 8.1 SP3 through SP6 can inadvertently remove entitlements for pages when an administrator edits the page definition label, which might allow remote attackers to bypass intended access restrictions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:weblogic_portal:8.1_sp6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp5:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T01:44Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0865",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1_sp6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/257",
          "name" : "BEA08-184.00",
          "refsource" : "BEA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29041",
          "name" : "29041",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019451",
          "name" : "1019451",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0613",
          "name" : "ADV-2008-0613",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP6 allows remote attackers to bypass entitlements for instances of a floatable WLP portlet via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:weblogic_portal:8.1_sp6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp5:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T01:44Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0866",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_workshop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/258",
          "name" : "BEA08-185.00",
          "refsource" : "BEA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29041",
          "name" : "29041",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019441",
          "name" : "1019441",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0611",
          "name" : "ADV-2008-0611",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Workshop allow remote attackers to inject arbitrary web script or HTML via an invalid action URI, which is not properly handled by NetUI page flows."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_workshop:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_workshop:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_workshop:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_workshop:8.1:sp5:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-21T01:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0867",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "aqualogic_interaction",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "plumtree_foundation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/259",
          "name" : "BEA08-186.00",
          "refsource" : "BEA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29040",
          "name" : "29040",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.procheckup.com/Vulnerability_PR06-12.php",
          "name" : "http://www.procheckup.com/Vulnerability_PR06-12.php",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488346/100/100/threaded",
          "name" : "20080219 PR06-12: XSS on BEA Plumtree Foundation and AquaLogic Interaction portals",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019440",
          "name" : "1019440",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0610",
          "name" : "ADV-2008-0610",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in portal/server.pt in BEA AquaLogic Interaction 6.1 through MP1 and Plumtree Foundation 6.0 through SP1 allows remote attackers to inject arbitrary web script or HTML via the name parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:aqualogic_interaction:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:aqualogic_interaction:6.1:mp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:plumtree_foundation:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:plumtree_foundation:6.0:sp1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-21T01:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0868",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/261",
          "name" : "BEA08-188.00",
          "refsource" : "BEA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29041",
          "name" : "29041",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019452",
          "name" : "1019452",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0613",
          "name" : "ADV-2008-0613",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Groupspace in BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 1 allows remote authenticated users to inject arbitrary web script or HTML via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:weblogic_portal:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-21T01:44Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0869",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "weblogic_workshop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "bea_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/263",
          "name" : "BEA08-189.00",
          "refsource" : "BEA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29041",
          "name" : "29041",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019438",
          "name" : "1019438",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0611",
          "name" : "ADV-2008-0611",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0612/references",
          "name" : "ADV-2008-0612",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a \"framework defined request parameter\" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_workshop:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_workshop:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_workshop:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_workshop:8.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_workshop:8.1:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:weblogic:10.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-21T01:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0870",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-59"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/264",
          "name" : "BEA08-190.00",
          "refsource" : "BEA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29041",
          "name" : "29041",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019442",
          "name" : "1019442",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0613",
          "name" : "ADV-2008-0613",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Administration Console to an http URI, which allows remote attackers to sniff the session."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:weblogic_portal:9.2:mp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:weblogic_portal:9.2:mp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:weblogic_portal:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T01:44Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0871",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "now",
            "product" : {
              "product_data" : [ {
                "product_name" : "sms_mms_gateway",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007.06.27",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/nowsmsz-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/nowsmsz-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/29003",
          "name" : "29003",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488365/100/100/threaded",
          "name" : "20080219 Multiple buffer-overflow in NowSMS v2007.06.27",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27896",
          "name" : "27896",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0615",
          "name" : "ADV-2008-0615",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5695",
          "name" : "5695",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute arbitrary code via a (1) long password in an Authorization header to the HTTP service or a (2) large packet to the SMPP service."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:now:sms_mms_gateway:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2007.06.27"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T19:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0872",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "smartertools",
            "product" : {
              "product_data" : [ {
                "product_name" : "smartermail_enterprise",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://es.geocities.com/jplopezy/SmarterMailXSS.txt",
          "name" : "http://es.geocities.com/jplopezy/SmarterMailXSS.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/29024",
          "name" : "29024",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3686",
          "name" : "3686",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488313/100/0/threaded",
          "name" : "20080219 SmarterMail Enterprise 4.3 - malformed mail XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27878",
          "name" : "27878",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019461",
          "name" : "1019461",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in SmarterTools SmarterMail Enterprise 4.3 allows remote attackers to inject arbitrary web script or HTML via a STYLE attribute of an element in the Subject field of an e-mail message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smartertools:smartermail_enterprise:4.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-21T19:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0873",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jlmzone",
            "product" : {
              "product_data" : [ {
                "product_name" : "classifieds",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3681",
          "name" : "3681",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488357/100/0/threaded",
          "name" : "20080219 XOOPS Module classifieds SQL Injection(cid)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27895",
          "name" : "27895",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5158",
          "name" : "5158",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the jlmZone Classifieds module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in an Adsview action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jlmzone:classifieds:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T19:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0874",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xoops",
            "product" : {
              "product_data" : [ {
                "product_name" : "eempregos_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3682",
          "name" : "3682",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488358/100/0/threaded",
          "name" : "20080219 XOOPS Module eEmpregos SQL Injection(cid)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27905",
          "name" : "27905",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5157",
          "name" : "5157",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the eEmpregos module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action."
        }, {
          "lang" : "en",
          "value" : "Additional information was found while analyzing this vulnerability.\r\n\r\nhttp://www.securityfocus.com/bid/27905"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xoops:eempregos_module:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T19:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0875",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hitachi",
            "product" : {
              "product_data" : [ {
                "product_name" : "eur_print_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "05-06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "05-06-_b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "05-08",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29030",
          "name" : "29030",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.hitachi-support.com/security_e/vuls_e/HS08-001_e/index-e.html",
          "name" : "http://www.hitachi-support.com/security_e/vuls_e/HS08-001_e/index-e.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27899",
          "name" : "27899",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0616",
          "name" : "ADV-2008-0616",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Hitachi EUR Print Manager, and related Client and Local Server products, 05-06 through 05-06-/B and 05-08 allows remote attackers to cause a denial of service (service hang or termination) via unspecified vectors related to \"unexpected data.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:eur_print_manager:05-06:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:eur_print_manager:05-06-_b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:eur_print_manager:05-08:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T19:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0876",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hitachi",
            "product" : {
              "product_data" : [ {
                "product_name" : "sewb3_mi-platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "01-00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-06-_a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-07",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-10-_a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-16-_b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-16-_c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-16-_f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-17-_f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "02-13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "02-14-_a",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sewb3_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "01-00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-06-_a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-10-_a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-16-_b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-16-_c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-16-_f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "01-17-_f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "02-13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "02-14-_a",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29028",
          "name" : "29028",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.hitachi-support.com/security_e/vuls_e/HS08-002_e/index-e.html",
          "name" : "http://www.hitachi-support.com/security_e/vuls_e/HS08-002_e/index-e.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27900",
          "name" : "27900",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0617",
          "name" : "ADV-2008-0617",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the SEWB3 messaging service in Hitachi SEWB3/PLATFORM and SEWB3/MI-PLATFORM 01-00 through 02-14-/A allows remote attackers to cause a denial of service (service outage) via \"invalid data.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-00:*:hi-ux_we2\\(3050_risc\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-00:*:hi-ux_we2\\(3050_sisc\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-00:*:hi-ux_we2\\(3050rx\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-00:*:hp-ux\\(9.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-04:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-06-_a:*:hi-ux_we2\\(3050_risc\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-06-_a:*:hi-ux_we2\\(3050_sisc\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-07:*:hi-ux_we2\\(3050rx\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-10:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-10-_a:*:hp-ux\\(9.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-11:*:hp-ux\\(10.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-16-_b:*:hi-ux_we2\\(3050rx\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-16-_b:*:hp-ux\\(10.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-16-_c:*:hp-ux\\(11.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-16-_f:*:hi-ux_we2\\(3050rx\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-16-_f:*:hp-ux\\(11.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-17:*:hp-ux\\(11.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:01-17-_f:*:hp-ux\\(11.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:02-13:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_mi-platform:02-14-_a:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-00:*:hi-ux_we2\\(3050_risc\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-00:*:hi-ux_we2\\(3050_sisc\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-00:*:hi-ux_we2\\(3050rx\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-00:*:hp-ux\\(9.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-04:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-06:*:hi-ux_we2\\(3050rx\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-06-_a:*:hi-ux_we2\\(3050_risc\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-06-_a:*:hi-ux_we2\\(3050_sisc\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-10:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-10-_a:*:hp-ux\\(9.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-11:*:hp-ux\\(10.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-16-_b:*:hi-ux_we2\\(3050rx\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-16-_b:*:hp-ux\\(10.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-16-_c:*:hp-ux\\(11.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-16-_f:*:hi-ux_we2\\(3050rx\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-16-_f:*:hp-ux\\(11.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-17:*:hp-ux\\(11.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:01-17-_f:*:hp-ux\\(11.x\\):*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:02-13:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:sewb3_platform:02-14-_a:*:solaris:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T19:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0877",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jinzora",
            "product" : {
              "product_data" : [ {
                "product_name" : "media_jukebox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29023",
          "name" : "29023",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3683",
          "name" : "3683",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488326/100/0/threaded",
          "name" : "20080219 [DSECRG-08-016] Jinzora 2.7.5 Multiple XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27876",
          "name" : "27876",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Jinzora Media Jukebox 2.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) frontend, (2) set_frontend, (3) jz_path, (4) theme, and (5) set_theme parameters to (a) index.php; the frontend, theme, and (6) language parameters to (b) ajax_request.php; the jz_path parameter to (c) slim.php; the frontend, theme, and jz_path parameters to (d) popup.php; the (13) PATH_INFO to index.php and (e) slim.php; and the (14) query parameter in a playlistedit action and (15) siteNewsData parameter in a sitenews action to (f) popup.php."
        }, {
          "lang" : "en",
          "value" : "During analysis additional information was found for this vulnerability.\r\n\r\nhttp://www.securityfocus.com/bid/27876/info"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jinzora:media_jukebox:2.7.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-21T19:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0878",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "runcms",
            "product" : {
              "product_data" : [ {
                "product_name" : "myannonces",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27902",
          "name" : "27902",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0619",
          "name" : "ADV-2008-0619",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40861",
          "name" : "myannonces-index-sql-injection(40861)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5156",
          "name" : "5156",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action."
        }, {
          "lang" : "en",
          "value" : "Additional information is available at the following securityfocus bid link: http://www.securityfocus.com/bid/27902/info"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:myannonces:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T19:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0879",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpnuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "web_links_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/126697/PHP-Nuke-Web-Links-SQL-Injection.html",
          "name" : "http://packetstormsecurity.com/files/126697/PHP-Nuke-Web-Links-SQL-Injection.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3684",
          "name" : "3684",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488356/100/0/threaded",
          "name" : "20080219 PHP-Nuke Module Web_Links SQL Injection(cid)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27894",
          "name" : "27894",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/67463",
          "name" : "67463",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40862",
          "name" : "weblinks-cid-sql-injection(40862)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in modules.php in the Web_Links module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewlink action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpnuke:web_links_module:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T19:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0880",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpnuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "easycontent_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27897",
          "name" : "27897",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5155",
          "name" : "5155",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the page_id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpnuke:easycontent_module:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T19:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0881",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpnuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "okul_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27909",
          "name" : "27909",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5159",
          "name" : "5159",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the okulid parameter in an okullar action."
        }, {
          "lang" : "en",
          "value" : "More information is available at the following securityfocus bid link: http://www.securityfocus.com/bid/27909/info"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpnuke:okul_module:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T19:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0882",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cups",
            "product" : {
              "product_data" : [ {
                "product_name" : "cups",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00000.html",
          "name" : "SUSE-SA:2008:012",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28994",
          "name" : "28994",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29067",
          "name" : "29067",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29120",
          "name" : "29120",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29132",
          "name" : "29132",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29251",
          "name" : "29251",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29485",
          "name" : "29485",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29603",
          "name" : "29603",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29634",
          "name" : "29634",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200804-01.xml",
          "name" : "GLSA-200804-01",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.cups.org/str.php?L2656",
          "name" : "http://www.cups.org/str.php?L2656",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1530",
          "name" : "DSA-1530",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:050",
          "name" : "MDVSA-2008:050",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:051",
          "name" : "MDVSA-2008:051",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0157.html",
          "name" : "RHSA-2008:0157",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27906",
          "name" : "27906",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019473",
          "name" : "1019473",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-598-1",
          "name" : "USN-598-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0623",
          "name" : "ADV-2008-0623",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=433758",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=433758",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9625",
          "name" : "oval:org.mitre.oval:def:9625",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00792.html",
          "name" : "FEDORA-2008-1901",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00832.html",
          "name" : "FEDORA-2008-1976",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation of a remote printer.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cups:cups:1.3.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T19:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0883",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "acrobat_reader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-59"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html",
          "name" : "SUSE-SR:2008:005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29229",
          "name" : "29229",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29242",
          "name" : "29242",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29425",
          "name" : "29425",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31136",
          "name" : "31136",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31352",
          "name" : "31352",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-240106-1",
          "name" : "240106",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/d8c48c63359fc807624182696d3d149c.html",
          "name" : "http://support.novell.com/techcenter/psdb/d8c48c63359fc807624182696d3d149c.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.adobe.com/support/security/advisories/apsa08-02.html",
          "name" : "http://www.adobe.com/support/security/advisories/apsa08-02.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200803-26.xml",
          "name" : "GLSA-200803-26",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0641.html",
          "name" : "RHSA-2008:0641",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28091",
          "name" : "28091",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019539",
          "name" : "1019539",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0765/references",
          "name" : "ADV-2008-0765",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2289",
          "name" : "ADV-2008-2289",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40987",
          "name" : "adobe-reader-acroread-symlink(40987)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "acroread in Adobe Acrobat Reader 8.1.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files related to SSL certificate handling."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:open_suse:10.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:open_suse:10.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:open_suse:10.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10:*:enterprise_desktop:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10:*:enterprise_server:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10:sp1:enterprise_desktop:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10.0:*:ppc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10.0:*:x86:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10.0:*:x86_64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10.1:*:ppc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10.1:*:x86:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10.1:*:x86_64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:suse:suse_linux_desktop:10:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:8.1.2:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 1.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-06T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0884",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "red_hat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://rhn.redhat.com/errata/RHSA-2008-0193.html",
          "name" : "RHSA-2008:0193",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29642",
          "name" : "29642",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019740",
          "name" : "1019740",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28557",
          "name" : "28557",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=435442",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=435442",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41584",
          "name" : "redhat-lsppeal4config-insecure-permissions(41584)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Replace function in the capp-lspp-config script in the (1) lspp-eal4-config-ibm and (2) capp-lspp-eal4-config-hp packages before 0.65-2 in Red Hat Enterprise Linux (RHEL) 5 uses lstat instead of stat to determine the /etc/pam.d/system-auth file permissions, leading to a change to world-writable permissions for the /etc/pam.d/system-auth-ac file, which allows local users to gain privileges by modifying this file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:red_hat:enterprise_linux:5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-04T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0886",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2008-0882.  Reason: This candidate is a duplicate of CVE-2008-0882.  Notes: All CVE users should reference CVE-2008-0882 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2008-02-29T19:44Z",
    "lastModifiedDate" : "2008-09-11T01:06Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0887",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnome",
            "product" : {
              "product_data" : [ {
                "product_name" : "screensaver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.20.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html",
          "name" : "SUSE-SR:2008:014",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35531",
          "name" : "35531",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2008-0197.html",
          "name" : "RHSA-2008:0197",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29595",
          "name" : "29595",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29606",
          "name" : "29606",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29742",
          "name" : "29742",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29759",
          "name" : "29759",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30967",
          "name" : "30967",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32691",
          "name" : "32691",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200804-12.xml",
          "name" : "GLSA-200804-12",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019749",
          "name" : "1019749",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:132",
          "name" : "MDVSA-2008:132",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0218.html",
          "name" : "RHSA-2008:0218",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28575",
          "name" : "28575",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-669-1",
          "name" : "USN-669-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=435773",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=435773",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10813",
          "name" : "oval:org.mitre.oval:def:10813",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00163.html",
          "name" : "FEDORA-2008-2967",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00206.html",
          "name" : "FEDORA-2008-3017",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "gnome-screensaver before 2.22.1, when a remote authentication server is enabled, crashes upon an unlock attempt during a network outage, which allows physically proximate attackers to gain access to the locked session, a related issue to CVE-2007-1859."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnome:screensaver:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.20.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.7
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-06T23:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0888",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "info-zip",
            "product" : {
              "product_data" : [ {
                "product_name" : "unzip",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html",
          "name" : "APPLE-SA-2010-03-29-1",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00008.html",
          "name" : "SUSE-SR:2008:007",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29392",
          "name" : "29392",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29406",
          "name" : "29406",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29415",
          "name" : "29415",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29427",
          "name" : "29427",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29432",
          "name" : "29432",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29440",
          "name" : "29440",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29495",
          "name" : "29495",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29681",
          "name" : "29681",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30535",
          "name" : "30535",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31204",
          "name" : "31204",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200804-06.xml",
          "name" : "GLSA-200804-06",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT4077",
          "name" : "http://support.apple.com/kb/HT4077",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0116",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0116",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0116",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0116",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1522",
          "name" : "DSA-1522",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.ipcop.org/index.php?name=News&file=article&sid=40",
          "name" : "http://www.ipcop.org/index.php?name=News&file=article&sid=40",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:068",
          "name" : "MDVSA-2008:068",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0196.html",
          "name" : "RHSA-2008:0196",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489967/100/0/threaded",
          "name" : "20080321 rPSA-2008-0116-1 unzip",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/493080/100/0/threaded",
          "name" : "20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28288",
          "name" : "28288",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019634",
          "name" : "1019634",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-589-1",
          "name" : "USN-589-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/security/advisories/VMSA-2008-0009.html",
          "name" : "http://www.vmware.com/security/advisories/VMSA-2008-0009.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0913/references",
          "name" : "ADV-2008-0913",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1744",
          "name" : "ADV-2008-1744",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41246",
          "name" : "unzip-inflatedynamic-code-execution(41246)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2317",
          "name" : "https://issues.rpath.com/browse/RPL-2317",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9733",
          "name" : "oval:org.mitre.oval:def:9733",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:info-zip:unzip:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-17T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0889",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "directory_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29482",
          "name" : "29482",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0191.html",
          "name" : "RHSA-2008:0191",
          "refsource" : "REDHAT",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28327",
          "name" : "28327",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019677",
          "name" : "1019677",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Red Hat Directory Server 8.0, when running on Red Hat Enterprise Linux, uses insecure permissions for the redhat-idm-console script, which allows local users to execute arbitrary code by modifying the script."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:redhat:directory_server:8.0:el4:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:redhat:directory_server:8.0:el5:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-20T00:44Z",
    "lastModifiedDate" : "2008-09-05T21:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0890",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "directory_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29350",
          "name" : "29350",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0173.html",
          "name" : "RHSA-2008:0173",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28204",
          "name" : "28204",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019577",
          "name" : "1019577",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41152",
          "name" : "rhds-jars-insecure-permissions(41152)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Red Hat Directory Server 7.1 before SP4 uses insecure permissions for certain directories, which allows local users to modify JAR files and execute arbitrary code via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:directory_server:*:sp3:*:*:*:*:*:*",
          "versionEndIncluding" : "7.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-12T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0891",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openssl",
            "product" : {
              "product_data" : [ {
                "product_name" : "openssl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.8f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8g",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://cert.fi/haavoittuvuudet/2008/advisory-openssl.html",
          "name" : "http://cert.fi/haavoittuvuudet/2008/advisory-openssl.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30405",
          "name" : "30405",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30460",
          "name" : "30460",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30825",
          "name" : "30825",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30852",
          "name" : "30852",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30868",
          "name" : "30868",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31228",
          "name" : "31228",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31288",
          "name" : "31288",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200806-08.xml",
          "name" : "GLSA-200806-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.562004",
          "name" : "SSA:2008-210-08",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=615606",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=615606",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=738400",
          "name" : "http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=738400",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/661475",
          "name" : "VU#661475",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:107",
          "name" : "MDVSA-2008:107",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.openssl.org/news/secadv_20080528.txt",
          "name" : "http://www.openssl.org/news/secadv_20080528.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29405",
          "name" : "29405",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020121",
          "name" : "1020121",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-620-1",
          "name" : "USN-620-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1680",
          "name" : "ADV-2008-1680",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1937/references",
          "name" : "ADV-2008-1937",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42666",
          "name" : "openssl-servername-dos(42666)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-May/msg01029.html",
          "name" : "FEDORA-2008-4723",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a malformed Client Hello packet.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:0.9.8g:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-05-29T16:32Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0892",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "directory_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "fedora_directory_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "red_hat",
            "product" : {
              "product_data" : [ {
                "product_name" : "directory_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01433676",
          "name" : "HPSBUX02324",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29761",
          "name" : "29761",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29826",
          "name" : "29826",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30114",
          "name" : "30114",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0199.html",
          "name" : "RHSA-2008:0199",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0201.html",
          "name" : "RHSA-2008:0201",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28802",
          "name" : "28802",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019856",
          "name" : "1019856",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1449/references",
          "name" : "ADV-2008-1449",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=437301",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=437301",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41840",
          "name" : "rhds-replmonitor-command-execution(41840)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00380.html",
          "name" : "FEDORA-2008-3214",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00386.html",
          "name" : "FEDORA-2008-3220",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, allows remote attackers to execute arbitrary commands."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:directory_server:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:red_hat:directory_server:8:el4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:red_hat:directory_server:8:el5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:fedora_directory_server:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-16T18:05Z",
    "lastModifiedDate" : "2018-10-30T16:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0893",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "directory_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29761",
          "name" : "29761",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29826",
          "name" : "29826",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0201.html",
          "name" : "RHSA-2008:0201",
          "refsource" : "REDHAT",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28802",
          "name" : "28802",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019857",
          "name" : "1019857",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=437320",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=437320",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41843",
          "name" : "rhds-cgiscripts-security-bypass(41843)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00380.html",
          "name" : "FEDORA-2008-3214",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00386.html",
          "name" : "FEDORA-2008-3220",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properly restrict access to CGI scripts, which allows remote attackers to perform administrative actions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:directory_server:8.0:el4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:directory_server:8.0:el5:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-16T18:05Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0894",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3685",
          "name" : "3685",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488264/100/0/threaded",
          "name" : "20080216 [HISPASEC] FireFox 2.0.0.11 and Opera 9.50 beta Remote Memory Information Leak, FireFox 2.0.0.11 Remote Denial of Service",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27947",
          "name" : "27947",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019487",
          "name" : "1019487",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=408076",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=408076",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Apple Safari might allow remote attackers to obtain potentially sensitive memory contents or cause a denial of service (crash) via a crafted (1) bitmap (BMP) or (2) GIF file, a related issue to CVE-2008-0420."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-21T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0895",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/265",
          "name" : "BEA08-191.00",
          "refsource" : "BEA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29041",
          "name" : "29041",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019443",
          "name" : "1019443",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0612/references",
          "name" : "ADV-2008-0612",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server and WebLogic Express 6.1 through 10.0 allows remote attackers to bypass authentication for application servlets via crafted request headers."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:10.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0896",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/266",
          "name" : "BEA08-192.00",
          "refsource" : "BEA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29041",
          "name" : "29041",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019453",
          "name" : "1019453",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0613",
          "name" : "ADV-2008-0613",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which allows attackers to bypass intended access restrictions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:weblogic_portal:9.2:mp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:weblogic_portal:10.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0897",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/267",
          "name" : "BEA08-193.00",
          "refsource" : "BEA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29041",
          "name" : "29041",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019444",
          "name" : "1019444",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0612/references",
          "name" : "ADV-2008-0612",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without \"receive\" permissions to bypass intended access restrictions and receive messages from a standalone JMS Topic or secured Distributed Topic member destination, related to durable subscriptions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:mp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:10.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:C/I:C/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.9
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 6.8,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0898",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/268",
          "name" : "BEA08-194.00",
          "refsource" : "BEA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29041",
          "name" : "29041",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019447",
          "name" : "1019447",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0612/references",
          "name" : "ADV-2008-0612",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The distributed queue feature in JMS in BEA WebLogic Server 9.0 through 10.0, in certain configurations, does not properly handle when a client cannot send a message to a member of a distributed queue, which allows remote authenticated users to bypass intended access restrictions for protected distributed queues."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:ga:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:ga:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:mp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:mp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:10.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0899",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/269",
          "name" : "BEA08-195.00",
          "refsource" : "BEA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29041",
          "name" : "29041",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019448",
          "name" : "1019448",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0612/references",
          "name" : "ADV-2008-0612",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Administration Console in BEA WebLogic Server and Express 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via URLs that are not properly handled by the Unexpected Exception Page."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:mp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:10.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0900",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "bea_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_express",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/270",
          "name" : "BEA08-196.00",
          "refsource" : "BEA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29041",
          "name" : "29041",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019439",
          "name" : "1019439",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0612/references",
          "name" : "ADV-2008-0612",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp5:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp6:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:mp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:weblogic_express:9.2:mp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:weblogic_express:10.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0901",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "bea_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0_mp1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-255"
          }, {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/271",
          "name" : "BEA08-197.00",
          "refsource" : "BEA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29041",
          "name" : "29041",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.s21sec.com/avisos/s21sec-040-en.txt",
          "name" : "http://www.s21sec.com/avisos/s21sec-040-en.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488686/100/0/threaded",
          "name" : "20080225 S21SEC-040-en: Infinite invalid authentication attempts possible in BEA WebLogic Server",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019449",
          "name" : "1019449",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0612/references",
          "name" : "ADV-2008-0612",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:mp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:mp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:weblogic_server:10.0_mp1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0902",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "bea_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0_mp1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/273",
          "name" : "BEA08-80.04",
          "refsource" : "BEA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29041",
          "name" : "29041",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0612/references",
          "name" : "ADV-2008-0612",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 6.1 through 10.0 MP1 allow remote attackers to inject arbitrary web script or HTML via unspecified samples.  NOTE: this might be the same issue as CVE-2007-2694."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:ga:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:ga:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:weblogic_server:10.0_mp1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0903",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_express",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/275",
          "name" : "BEA08-199.00",
          "refsource" : "BEA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29041",
          "name" : "29041",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019450",
          "name" : "1019450",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0608/references",
          "name" : "ADV-2008-0608",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the BEA WebLogic Server and Express proxy plugin, as distributed before November 2007 and before 9.2 MP3 and 10.0 MP2, allows remote attackers to cause a denial of service (web server crash) via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:weblogic_express:*:mp2:*:*:*:*:*:*",
          "versionEndIncluding" : "10.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:weblogic_server:*:mp2:*:*:*:*:*:*",
          "versionEndIncluding" : "10.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0904",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "aqualogic_interaction",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2_mp1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "plumtree_collaboration",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1_sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1_sp2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/276",
          "name" : "BEA08-200.00",
          "refsource" : "BEA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://osvdb.org/41881",
          "name" : "41881",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28991",
          "name" : "28991",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019437",
          "name" : "1019437",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0607/references",
          "name" : "ADV-2008-0607",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remote attackers to read arbitrary files via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:aqualogic_interaction:4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:aqualogic_interaction:4.2_mp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:plumtree_collaboration:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:plumtree_collaboration:4.1_sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea_systems:plumtree_collaboration:4.1_sp2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0905",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "meo",
            "product" : {
              "product_data" : [ {
                "product_name" : "globsy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29047",
          "name" : "29047",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27910",
          "name" : "27910",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5162",
          "name" : "5162",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in globsy_edit.php in Globsy 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:meo:globsy:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0906",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php-nuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "php-nuke_module_docum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27912",
          "name" : "27912",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40720",
          "name" : "docum-modules-sql-injection(40720)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5161",
          "name" : "5161",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle operation."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php-nuke:php-nuke_module_docum:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0907",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php-nuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "inhalt_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27886",
          "name" : "27886",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5163",
          "name" : "5163",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php-nuke:inhalt_module:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0908",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "schoolwires",
            "product" : {
              "product_data" : [ {
                "product_name" : "academic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29034",
          "name" : "29034",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27903",
          "name" : "27903",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40687",
          "name" : "schoolwires-browse-sql-injection(40687)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in browse.asp in Schoolwires Academic Portal allows remote attackers to execute arbitrary SQL commands via the c parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:schoolwires:academic_portal:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0909",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "schoolwires",
            "product" : {
              "product_data" : [ {
                "product_name" : "academic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29034",
          "name" : "29034",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27903",
          "name" : "27903",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in browse.asp in Schoolwires Academic Portal allows remote attackers to inject arbitrary web script or HTML via the c parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:schoolwires:academic_portal:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-22T21:44Z",
    "lastModifiedDate" : "2008-09-05T21:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0910",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "f-secure",
            "product" : {
              "product_data" : [ {
                "product_name" : "f-secure_anti-virus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2008",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "f-secure_anti-virus_client_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "f-secure_anti-virus_for_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.65",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "f-secure_anti-virus_for_workstations",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "f-secure_anti-virus_linux_client_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.53",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "f-secure_internet_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2008",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "f-secure_protection_service_for_business",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.00",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "f-secure_protection_service_for_consumers",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.00",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28919",
          "name" : "28919",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.f-secure.com/security/fsc-2008-1.shtml",
          "name" : "http://www.f-secure.com/security/fsc-2008-1.shtml",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019405",
          "name" : "1019405",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019412",
          "name" : "1019412",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019413",
          "name" : "1019413",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0544/references",
          "name" : "ADV-2008-0544",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40480",
          "name" : "fsecure-cab-rar-security-bypass(40480)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted RAR archive.  NOTE: this might be related to CVE-2008-0792."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:2007:second_edition:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:2008:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_client_security:6.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_client_security:6.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_client_security:7.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_client_security:7.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_for_linux:4.65:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_for_workstations:5.44:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_for_workstations:7.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_for_workstations:7.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_linux_client_security:5.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus_linux_client_security:5.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_internet_security:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_internet_security:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_internet_security:2007:second_edition:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_internet_security:2008:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_protection_service_for_business:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.00"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_protection_service_for_consumers:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.00"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T22:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0911",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "iscripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "multicart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29018",
          "name" : "29018",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27916",
          "name" : "27916",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5166",
          "name" : "5166",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commands via the productid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:iscripts:multicart:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T23:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0912",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sybase",
            "product" : {
              "product_data" : [ {
                "product_name" : "mobilink",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0.1.3629",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "sql_anywhere",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0.1.3415",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/mobilinkhof-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/mobilinkhof-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/29045",
          "name" : "29045",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3691",
          "name" : "3691",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488409/100/0/threaded",
          "name" : "20080220 Heap overflow in Sybase MobiLink 10.0.1.3629",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/490259/100/0/threaded",
          "name" : "20080328 Re: Heap overflow in Sybase MobiLink 10.0.1.3629",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27914",
          "name" : "27914",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019469",
          "name" : "1019469",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0626",
          "name" : "ADV-2008-0626",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415 and probably other products, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long (1) username, (2) version, or (3) remote ID.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sybase:mobilink:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "10.0.1.3629"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sybase:sql_anywhere:10.0.1.3415:*:developer_edition:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0913",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "invision_power_services",
            "product" : {
              "product_data" : [ {
                "product_name" : "invision_power_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forums.invisionpower.com/index.php?showtopic=269961",
          "name" : "http://forums.invisionpower.com/index.php?showtopic=269961",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29055",
          "name" : "29055",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB or IP.Board) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via crafted BBCodes in an unspecified context."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.3.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-22T23:44Z",
    "lastModifiedDate" : "2008-09-05T21:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0914",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ipdiva",
            "product" : {
              "product_data" : [ {
                "product_name" : "ipdiva",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060315.html",
          "name" : "20080214 DOINGSOFT-2008-02-11-002 IP Diva VPN SSL many XSS attacks",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28963",
          "name" : "28963",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3690",
          "name" : "3690",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488143/100/100/threaded",
          "name" : "20080214 DOINGSOFT-2008-02-11-002 IP Diva VPN SSL many XSS attacks",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488204/100/0/threaded",
          "name" : "20080214 Re: DOINGSOFT-2008-02-11-002 IP Diva VPN SSL many XSS attacks",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27800",
          "name" : "27800",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40545",
          "name" : "ipdivaserver-unspecified-xss(40545)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in the Mediation server in IPdiva SSL VPN Server 2.2 before 2.2.8.84 and 2.3 before 2.3.2.14 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ipdiva:ipdiva:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ipdiva:ipdiva:2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-22T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0915",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ipdiva",
            "product" : {
              "product_data" : [ {
                "product_name" : "ipdiva",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2.8",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "2.3.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060314.html",
          "name" : "20080214 DOINGSOFT-2008-02-11 - IPDiva VPN SSL Brute force attack",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28963",
          "name" : "28963",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3692",
          "name" : "3692",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488133/100/100/threaded",
          "name" : "20080214 DOINGSOFT-2008-02-11 - IPDiva VPN SSL Brute force attack",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27800",
          "name" : "27800",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Mediation server in IPdiva SSL VPN Server 2.2 before 2.2.8.84 and 2.3 before 2.3.2.14 stores the number of remaining allowed login attempts in a cookie, which makes it easier for remote attackers to conduct brute force attacks by manipulating this cookie's value."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ipdiva:ipdiva:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.2.8"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ipdiva:ipdiva:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.3.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0916",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "highwood_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "hwdvideoshare",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29044",
          "name" : "29044",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27907",
          "name" : "27907",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40711",
          "name" : "hwdvideoshare-index-sql-injection(40711)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5160",
          "name" : "5160",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla!  allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a viewcategory action to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:highwood_design:hwdvideoshare:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T23:44Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0917",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tor_world",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_vote",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "i-navigator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "interactive_bbs",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mobile_frontier",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "quotes_of_the_day",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "simple_bbs",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "simple_vote",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "tor_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "tor_news",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.21",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "tor_search",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://download.torworld.com/bug/20080221.html",
          "name" : "http://download.torworld.com/bug/20080221.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://jvn.jp/jp/JVN%2354593414/index.html",
          "name" : "JVN#54593414",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29039",
          "name" : "29039",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27919",
          "name" : "27919",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and earlier, and Com Vote 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor_world:com_vote:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor_world:i-navigator:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor_world:interactive_bbs:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor_world:mobile_frontier:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor_world:quotes_of_the_day:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor_world:simple_bbs:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor_world:simple_vote:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor_world:tor_board:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor_world:tor_news:1.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor_world:tor_search:1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-22T23:44Z",
    "lastModifiedDate" : "2008-09-05T21:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0918",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "astats",
            "product" : {
              "product_data" : [ {
                "product_name" : "astatspro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "com_astatspro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29008",
          "name" : "29008",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40852",
          "name" : "astatspro-countdlorlink-sql-injection(40852)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in includes/count_dl_or_link.inc.php in the astatsPRO (com_astatspro) 1.0.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to getfile.php, a different vector than CVE-2008-0839. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:astats:astatspro:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:com_astatspro:1.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0919",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "open_source_security_information_management",
            "product" : {
              "product_data" : [ {
                "product_name" : "os-sim",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3.1alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.9_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.9_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.9_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.9_rc4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/42006",
          "name" : "42006",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29046",
          "name" : "29046",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3689",
          "name" : "3689",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488450/100/0/threaded",
          "name" : "20080221 SQL-injection, XSS in OSSIM (Open Source Security Information Management)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488617/100/0/threaded",
          "name" : "20080222 Re: SQL-injection, XSS in OSSIM (Open Source Security Information Management)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488697/100/0/threaded",
          "name" : "20080225 Re: Re: SQL-injection, XSS in OSSIM (Open Source Security Information Management)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27929",
          "name" : "27929",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5171",
          "name" : "5171",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 and earlier allows remote attackers to inject arbitrary web script or HTML via the dest parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.1alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.2alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.3.1alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.3alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.9.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.9.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.9.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.9.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.9.9_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.9.9_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.9.9_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:0.9.9_rc4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-22T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0920",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "open_source_security_information_management",
            "product" : {
              "product_data" : [ {
                "product_name" : "os-sim",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29046",
          "name" : "29046",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3689",
          "name" : "3689",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488450/100/0/threaded",
          "name" : "20080221 SQL-injection, XSS in OSSIM (Open Source Security Information Management)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488617/100/0/threaded",
          "name" : "20080222 Re: SQL-injection, XSS in OSSIM (Open Source Security Information Management)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27927",
          "name" : "27927",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5171",
          "name" : "5171",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a validation regular expression."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_source_security_information_management:os-sim:*:rc5:*:*:*:*:*:*",
          "versionEndIncluding" : "0.9.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0921",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "becontent",
            "product" : {
              "product_data" : [ {
                "product_name" : "becontent",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29061",
          "name" : "29061",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27928",
          "name" : "27928",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5170",
          "name" : "5170",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in news.php in beContent 0.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:becontent:becontent:0.3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T23:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0922",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php-nuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "manuales",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27933",
          "name" : "27933",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5168",
          "name" : "5168",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewdownload action to modules.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php-nuke:manuales:0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-22T23:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0923",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vmware",
            "product" : {
              "product_data" : [ {
                "product_name" : "ace",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "vmware_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1_build_19317",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "vmware_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3_build_34685",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1004034",
          "name" : "http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1004034",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060457.html",
          "name" : "20080225 CORE-2007-0930 Path Traversal vulnerability in VMware's shared folders implementation",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.vmware.com/pipermail/security-announce/2008/000008.html",
          "name" : "[security-announce] 20080317 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29117",
          "name" : "29117",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3700",
          "name" : "3700",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.coresecurity.com/?action=item&id=2129",
          "name" : "http://www.coresecurity.com/?action=item&id=2129",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488725/100/0/threaded",
          "name" : "20080225 CORE-2007-0930 Path Traversal vulnerability in VMware's shared folders implementation",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489739/100/0/threaded",
          "name" : "20080318 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27944",
          "name" : "27944",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28276",
          "name" : "28276",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019493",
          "name" : "1019493",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/security/advisories/VMSA-2008-0005.html",
          "name" : "http://www.vmware.com/security/advisories/VMSA-2008-0005.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html",
          "name" : "http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/support/player/doc/releasenotes_player.html",
          "name" : "http://www.vmware.com/support/player/doc/releasenotes_player.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/support/player2/doc/releasenotes_player2.html",
          "name" : "http://www.vmware.com/support/player2/doc/releasenotes_player2.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html",
          "name" : "http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html",
          "name" : "http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0679",
          "name" : "ADV-2008-0679",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0905/references",
          "name" : "ADV-2008-0905",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40837",
          "name" : "vmware-sharedfolders-directory-traversal(40837)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows guest OS users to read and write arbitrary files on the host OS via a multibyte string that produces a wide character string containing .. (dot dot) sequences, which bypasses the protection mechanism, as demonstrated using a \"%c0%2e%c0%2e\" string."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:ace:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:ace:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:ace:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:ace:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:ace:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_player:1.0.1_build_19317:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_player:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_player:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_workstation:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_workstation:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:4.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:5.5.3_build_34685:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:5.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-26T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0924",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "novell",
            "product" : {
              "product_data" : [ {
                "product_name" : "edirectory",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.7.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29476",
          "name" : "29476",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/490117/100/0/threaded",
          "name" : "20080326 ZDI-08-013: Novell eDirectory for Linux Stack Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28434",
          "name" : "28434",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019692",
          "name" : "1019692",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0987/references",
          "name" : "ADV-2008-0987",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-013/",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-013/",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://secure-support.novell.com/KanisaPlatform/Publishing/411/3382120_f.SAL_Public.html",
          "name" : "https://secure-support.novell.com/KanisaPlatform/Publishing/411/3382120_f.SAL_Public.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the DoLBURPRequest function in libnldap in ndsd in Novell eDirectory 8.7.3.9 and earlier, and 8.8.1 and earlier in the 8.8.x series, allows remote attackers to cause a denial of service (daemon crash or CPU consumption) or execute arbitrary code via a long delRequest LDAP Extended Request message, probably involving a long Distinguished Name (DN) field."
        }, {
          "lang" : "en",
          "value" : "During analysis the following related page was found.\r\n\r\nhttp://www.zerodayinitiative.com/advisories/ZDI-08-013/"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "8.7",
          "versionEndIncluding" : "8.7.3.9"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "8.8",
          "versionEndIncluding" : "8.8.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-28T18:44Z",
    "lastModifiedDate" : "2018-11-01T15:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0925",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "novell",
            "product" : {
              "product_data" : [ {
                "product_name" : "edirectory",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.7.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.8.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/30748",
          "name" : "30748",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1020321",
          "name" : "1020321",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5037180.html",
          "name" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5037180.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5037181.html",
          "name" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5037181.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/support/viewContent.do?externalId=3460217&sliceId=1",
          "name" : "http://www.novell.com/support/viewContent.do?externalId=3460217&sliceId=1",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29782",
          "name" : "29782",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1863/references",
          "name" : "ADV-2008-1863",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/43151",
          "name" : "novell-edirectory-imonitor-xss(43151)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the iMonitor interface in Novell eDirectory 8.7.3.x before 8.7.3 sp10, and 8.8.x before 8.8.2 ftf2, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters that are used within \"error messages of the HTTP stack.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.7.3.9:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.7.3.9:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.7.3.9:*:windows_2000:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.7.3.9:*:windows_2003:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.8:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.8:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.8:*:windows_2000:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.8:*:windows_2003:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.8.1:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.8.1:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.8.1:*:windows_2000:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.8.1:*:windows_2003:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.8.2:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.8.2:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.8.2:*:windows_2000:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.8.2:*:windows_2003:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-06-18T19:41Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0926",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "novell",
            "product" : {
              "product_data" : [ {
                "product_name" : "edirectory",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.12a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.7.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.7.3.8_presp9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.7.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.7.3.10",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "8.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29527",
          "name" : "29527",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/491621/100/0/threaded",
          "name" : "20080505 Novell eDirectory unauthenticated access to SOAP interface",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28441",
          "name" : "28441",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019691",
          "name" : "1019691",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0988/references",
          "name" : "ADV-2008-0988",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41426",
          "name" : "novell-edirectory-embox-unspecified(41426)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://secure-support.novell.com/KanisaPlatform/Publishing/876/3866911_f.SAL_Public.html",
          "name" : "https://secure-support.novell.com/KanisaPlatform/Publishing/876/3866911_f.SAL_Public.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.5.12a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.5.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.7.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.7.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.7.3.8_presp9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.7.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.7.3.10"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:edirectory:8.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-28T18:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0927",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows-nt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29805",
          "name" : "29805",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.novell.com/support/viewContent.do?externalId=3829452&sliceId=1",
          "name" : "http://www.novell.com/support/viewContent.do?externalId=3829452&sliceId=1",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/491622/100/0/threaded",
          "name" : "20080505 Novell eDirectory DoS via HTTP headers",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28757",
          "name" : "28757",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019836",
          "name" : "1019836",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1217/references",
          "name" : "ADV-2008-1217",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41787",
          "name" : "novell-edirectory-dhost-dos(41787)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5547",
          "name" : "5547",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with (1) multiple Connection headers or (2) a Connection header with multiple comma-separated values.  NOTE: this might be similar to CVE-2008-1777."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:novell:edirectory:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "8.7.3.9"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:novell:edirectory:*:*:*:*:*:*:*:*",
            "versionStartIncluding" : "8.8",
            "versionEndExcluding" : "8.8.2"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:2000:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:2003:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-14T16:05Z",
    "lastModifiedDate" : "2018-10-31T19:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0928",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "qemu",
            "product" : {
              "product_data" : [ {
                "product_name" : "qemu",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html",
          "name" : "SUSE-SR:2009:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=debian-security&m=120343592917055&w=2",
          "name" : "[debian-security] 20080219 qemu unchecked block read/write vulnerability",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29081",
          "name" : "29081",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29129",
          "name" : "29129",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29136",
          "name" : "29136",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29172",
          "name" : "29172",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29963",
          "name" : "29963",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/34642",
          "name" : "34642",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/35031",
          "name" : "35031",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2009/dsa-1799",
          "name" : "DSA-1799",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:162",
          "name" : "MDVSA-2008:162",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2009:016",
          "name" : "MDVSA-2009:016",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-package-announce/2008-February/msg00830.html",
          "name" : "FEDORA-2008-1973",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-package-announce/2008-February/msg00850.html",
          "name" : "FEDORA-2008-1993",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0194.html",
          "name" : "RHSA-2008:0194",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28001",
          "name" : "28001",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=433560",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=433560",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9706",
          "name" : "oval:org.mitre.oval:def:9706",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00852.html",
          "name" : "FEDORA-2008-1995",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00857.html",
          "name" : "FEDORA-2008-2001",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00900.html",
          "name" : "FEDORA-2008-2057",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00957.html",
          "name" : "FEDORA-2008-2083",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qemu:qemu:0.9.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.7
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-03T22:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0929",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2008-02-25T22:44Z",
    "lastModifiedDate" : "2008-09-11T01:06Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0930",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freshmeat",
            "product" : {
              "product_data" : [ {
                "product_name" : "xwine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-59"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=468050",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=468050",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29125",
          "name" : "29125",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29452",
          "name" : "29452",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1526",
          "name" : "DSA-1526",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28049",
          "name" : "28049",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "w_editeur.c in XWine 1.0.1 for Debian GNU/Linux allows local users to overwrite or print arbitrary files via a symlink attack on the temporaire temporary file.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:freshmeat:xwine:1.0.1:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-04T00:44Z",
    "lastModifiedDate" : "2008-09-05T21:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0931",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xwine",
            "product" : {
              "product_data" : [ {
                "product_name" : "xwine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=468050",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=468050",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29125",
          "name" : "29125",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29452",
          "name" : "29452",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1526",
          "name" : "DSA-1526",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28369",
          "name" : "28369",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "w_export.c in XWine 1.0.1 on Debian GNU/Linux sets insecure permissions (0666) for /etc/wine/config, which might allow local users to execute arbitrary commands or cause a denial of service by modifying the file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:xwine:xwine:1.0.1:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:N/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-04T00:44Z",
    "lastModifiedDate" : "2008-09-05T21:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0932",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "the_sword_project",
            "product" : {
              "product_data" : [ {
                "product_name" : "diatheke_front_end",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.9",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "sword",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=466449",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=466449",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25400",
          "name" : "25400",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29012",
          "name" : "29012",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29115",
          "name" : "29115",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29181",
          "name" : "29181",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-06.xml",
          "name" : "GLSA-200803-06",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1508",
          "name" : "DSA-1508",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27874",
          "name" : "27874",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27987",
          "name" : "27987",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0670/references",
          "name" : "ADV-2008-0670",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=433723",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=433723",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00769.html",
          "name" : "FEDORA-2008-1922",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00806.html",
          "name" : "FEDORA-2008-1951",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "diatheke.pl in The SWORD Project Diatheke 1.5.9 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the range parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:alpha:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:amd64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:arm:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:hppa:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:ia-32:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:ia-64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:m68k:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:mips:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:mipsel:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:ppc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:s-390:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:sparc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:r1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:alpha:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:amd64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:arm:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:hppa:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:ia-32:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:ia-64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:m68k:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:mips:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:mipsel:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:powerpc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:s-390:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:sparc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:fedora:7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:fedora:8:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:the_sword_project:diatheke_front_end:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "1.5.9"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:the_sword_project:sword:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "1.5.9"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T21:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0933",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-362"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29052",
          "name" : "29052",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-231466-1",
          "name" : "231466",
          "refsource" : "SUNALERT",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27941",
          "name" : "27941",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019490",
          "name" : "1019490",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0642",
          "name" : "ADV-2008-0642",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5476",
          "name" : "oval:org.mitre.oval:def:5476",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple race conditions in the CPU Performance Counters (cpc) subsystem in the kernel in Sun Solaris 10 allow local users to cause a denial of service (panic) via unspecified vectors related to kcpc_unbind and kcpc_restore."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:x86_sparc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.7
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T18:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0934",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nukec",
            "product" : {
              "product_data" : [ {
                "product_name" : "nukec",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "php-nuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "nukec_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27937",
          "name" : "27937",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5172",
          "name" : "5172",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in modules.php in the NukeC 2.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id_catg parameter in a ViewCatg action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nukec:nukec:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php-nuke:nukec_module:2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T18:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0935",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "novell",
            "product" : {
              "product_data" : [ {
                "product_name" : "iprint",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.32",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "iprint_client",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.32",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://download.novell.com/Download?buildid=prBBH4JpImA~",
          "name" : "http://download.novell.com/Download?buildid=prBBH4JpImA~",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/27994",
          "name" : "27994",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27939",
          "name" : "27939",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019489",
          "name" : "1019489",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0639",
          "name" : "ADV-2008-0639",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the Novell iPrint Control ActiveX control in ienipp.ocx in Novell iPrint Client before 4.34 allows remote attackers to execute arbitrary code via a long argument to the ExecuteRequest method."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:iprint:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.32"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:iprint_client:4.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:iprint_client:4.32:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T18:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0936",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xoops",
            "product" : {
              "product_data" : [ {
                "product_name" : "prayer_list_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.04",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120362358919492&w=2",
          "name" : "20080221 XOOPS Module prayerlist SQL Injection(cid)",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/29063",
          "name" : "29063",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27934",
          "name" : "27934",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Prayer List (prayerlist) 1.04 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xoops:prayer_list_module:1.04:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T18:44Z",
    "lastModifiedDate" : "2008-09-05T21:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0937",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tinyevent",
            "product" : {
              "product_data" : [ {
                "product_name" : "tinyevent",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.01",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "xoops",
            "product" : {
              "product_data" : [ {
                "product_name" : "tiny_event_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.01",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120361694407815&w=2",
          "name" : "20080221 XOOPS Module tinyevent-print SQL Injection(id)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29073",
          "name" : "29073",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27931",
          "name" : "27931",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter in a print action, a different vector than CVE-2007-1811."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tinyevent:tinyevent:1.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xoops:tiny_event_module:1.01:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T18:44Z",
    "lastModifiedDate" : "2008-09-05T21:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0938",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29037",
          "name" : "29037",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-231803-1",
          "name" : "231803",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27942",
          "name" : "27942",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019483",
          "name" : "1019483",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0640",
          "name" : "ADV-2008-0640",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5451",
          "name" : "oval:org.mitre.oval:def:5451",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the dynamic tracing framework (DTrace) in Sun Solaris 10 allows local users with PRIV_DTRACE_USER or PRIV_DTRACE_PROC privileges to obtain sensitive kernel information via unspecified vectors, a different vulnerability than CVE-2007-4126."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10:*:x86:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.7
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T18:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0939",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "photo_album_plugin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://me.mywebsight.ws/web/wppa/",
          "name" : "http://me.mywebsight.ws/web/wppa/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28988",
          "name" : "28988",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3693",
          "name" : "3693",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://weblogtoolscollection.com/archives/2008/02/21/photo-album-plugin-vulnerabilities/",
          "name" : "http://weblogtoolscollection.com/archives/2008/02/21/photo-album-plugin-vulnerabilities/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488290",
          "name" : "20080216 WordPress album PHOTO SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27832",
          "name" : "27832",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0586",
          "name" : "ADV-2008-0586",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40599",
          "name" : "photoalbum-index-sql-injection(40599)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5135",
          "name" : "5135",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the photo parameter to index.php, used by the wppa_photo_name function; or (2) the album parameter to index.php, used by the wppa_album_name function.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:photo_album_plugin:1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T20:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0940",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webgui",
            "product" : {
              "product_data" : [ {
                "product_name" : "webgui",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.23",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28967",
          "name" : "28967",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.plainblack.com/getwebgui/advisories/webgui-7_4_24-stable-released",
          "name" : "http://www.plainblack.com/getwebgui/advisories/webgui-7_4_24-stable-released",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27869",
          "name" : "27869",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before 7.4.24 allows remote attackers to inject arbitrary web script or HTML when creating a username, a different vulnerability than CVE-2007-0407."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webgui:webgui:7.4.23:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-25T20:44Z",
    "lastModifiedDate" : "2008-09-05T21:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0941",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aeries",
            "product" : {
              "product_data" : [ {
                "product_name" : "aeries_student_information_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.7.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8.2.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29053",
          "name" : "29053",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3694",
          "name" : "3694",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488430/100/0/threaded",
          "name" : "20080221 aeries browser interface(ABI) 3.8.2.8 XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27924",
          "name" : "27924",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40756",
          "name" : "abi-newevent-xss(40756)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Eagle Software Aeries Browser Interface (ABI) 3.8.2.8 allows remote authenticated users to inject arbitrary web script or HTML via an event."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aeries:aeries_student_information_system:3.7.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aeries:aeries_student_information_system:3.8.2.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-25T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0942",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aeries",
            "product" : {
              "product_data" : [ {
                "product_name" : "aeries_student_information_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.7.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8.2.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3695",
          "name" : "3695",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488456/100/0/threaded",
          "name" : "20080221 aeries browser interface(ABI) 3.8.2.8 Remote SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27924",
          "name" : "27924",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40847",
          "name" : "abi-gradebookstuscores-sql-injection(40847)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in GradebookStuScores.asp in Eagle Software Aeries Browser Interface (ABI) 3.8.2.8 allows remote attackers to execute arbitrary SQL commands via the GrdBk parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aeries:aeries_student_information_system:3.7.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aeries:aeries_student_information_system:3.8.2.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0943",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aeries",
            "product" : {
              "product_data" : [ {
                "product_name" : "aeries_student_information_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.7.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8.2.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29053",
          "name" : "29053",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3696",
          "name" : "3696",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488428/100/0/threaded",
          "name" : "20080221 aeries browser interface(ABI) 3.7.2.2 Remote SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27924",
          "name" : "27924",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40757",
          "name" : "abi-fcterm-sql-injection(40757)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) FC parameter to Comments.asp, or the Term parameter to (2) Labels.asp or (3) ClassList.asp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aeries:aeries_student_information_system:3.7.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aeries:aeries_student_information_system:3.8.2.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0944",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ipswitch",
            "product" : {
              "product_data" : [ {
                "product_name" : "instant_messaging",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/ipsimene-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/ipsimene-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/28824",
          "name" : "28824",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3697",
          "name" : "3697",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487748/100/200/threaded",
          "name" : "20080207 Multiple vulnerabilities in Ipswitch Instant Messaging 2.0.8.1",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27677",
          "name" : "27677",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote attackers to cause a denial of service (NULL dereference and application crash) via a version field containing zero."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ipswitch:instant_messaging:2.0.8.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0945",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ipswitch",
            "product" : {
              "product_data" : [ {
                "product_name" : "imserver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.8.1",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "instant_messaging",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.8.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/ipsimene-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/ipsimene-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://aluigi.org/poc/ipsimene.zip",
          "name" : "http://aluigi.org/poc/ipsimene.zip",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28824",
          "name" : "28824",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3697",
          "name" : "3697",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487748/100/200/threaded",
          "name" : "20080207 Multiple vulnerabilities in Ipswitch Instant Messaging 2.0.8.1",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27677",
          "name" : "27677",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the logging function in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in an IP address field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ipswitch:imserver:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.8.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ipswitch:instant_messaging:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.8.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0946",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ipswitch",
            "product" : {
              "product_data" : [ {
                "product_name" : "imserver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.8.1",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "instant_messaging",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.8.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/ipsimene-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/ipsimene-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://aluigi.org/poc/ipsimene.zip",
          "name" : "http://aluigi.org/poc/ipsimene.zip",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3697",
          "name" : "3697",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487748/100/200/threaded",
          "name" : "20080207 Multiple vulnerabilities in Ipswitch Instant Messaging 2.0.8.1",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27677",
          "name" : "27677",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to create arbitrary empty files via a .. (dot dot) in the recipient field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ipswitch:imserver:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.8.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ipswitch:instant_messaging:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.8.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T21:44Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0947",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mit",
            "product" : {
              "product_data" : [ {
                "product_name" : "kerberos_5",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.html",
          "name" : "SUSE-SA:2008:016",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=130497213107107&w=2",
          "name" : "SSRT100495",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29424",
          "name" : "29424",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29428",
          "name" : "29428",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29435",
          "name" : "29435",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29438",
          "name" : "29438",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29451",
          "name" : "29451",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29457",
          "name" : "29457",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29462",
          "name" : "29462",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29464",
          "name" : "29464",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29516",
          "name" : "29516",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29663",
          "name" : "29663",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-31.xml",
          "name" : "GLSA-200803-31",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3752",
          "name" : "3752",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html",
          "name" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html",
          "name" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-002.txt",
          "name" : "http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-002.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0112",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0112",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1524",
          "name" : "DSA-1524",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/374121",
          "name" : "VU#374121",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:069",
          "name" : "MDVSA-2008:069",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:070",
          "name" : "MDVSA-2008:070",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0164.html",
          "name" : "RHSA-2008:0164",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489762/100/0/threaded",
          "name" : "20080318 MITKRB5-SA-2008-001: double-free, uninitialized data vulnerabilities in krb5kdc",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489784/100/0/threaded",
          "name" : "20080318 MITKRB5-SA-2008-002: array overrun in RPC library used by kadmin (resend, corrected subject)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489883/100/0/threaded",
          "name" : "20080319 rPSA-2008-0112-1 krb5 krb5-server krb5-services krb5-test krb5-workstation",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28302",
          "name" : "28302",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019631",
          "name" : "1019631",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-587-1",
          "name" : "USN-587-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079B.html",
          "name" : "TA08-079B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0922/references",
          "name" : "ADV-2008-0922",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1102/references",
          "name" : "ADV-2008-1102",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41273",
          "name" : "krb5-rpclibrary-bo(41273)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10984",
          "name" : "oval:org.mitre.oval:def:10984",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html",
          "name" : "FEDORA-2008-2637",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html",
          "name" : "FEDORA-2008-2647",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execute arbitrary code by triggering a large number of open file descriptors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:1.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:1.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:1.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:1.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:1.6.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-19T00:44Z",
    "lastModifiedDate" : "2020-01-21T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0948",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mit",
            "product" : {
              "product_data" : [ {
                "product_name" : "kerberos_5",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.html",
          "name" : "SUSE-SA:2008:016",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=130497213107107&w=2",
          "name" : "SSRT100495",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29423",
          "name" : "29423",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29424",
          "name" : "29424",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29428",
          "name" : "29428",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29663",
          "name" : "29663",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30535",
          "name" : "30535",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3752",
          "name" : "3752",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html",
          "name" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html",
          "name" : "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-002.txt",
          "name" : "http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-002.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/374121",
          "name" : "VU#374121",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0181.html",
          "name" : "RHSA-2008:0181",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489762/100/0/threaded",
          "name" : "20080318 MITKRB5-SA-2008-001: double-free, uninitialized data vulnerabilities in krb5kdc",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489784/100/0/threaded",
          "name" : "20080318 MITKRB5-SA-2008-002: array overrun in RPC library used by kadmin (resend, corrected subject)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/493080/100/0/threaded",
          "name" : "20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28302",
          "name" : "28302",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019631",
          "name" : "1019631",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079B.html",
          "name" : "TA08-079B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vmware.com/security/advisories/VMSA-2008-0009.html",
          "name" : "http://www.vmware.com/security/advisories/VMSA-2008-0009.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0922/references",
          "name" : "ADV-2008-0922",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1102/references",
          "name" : "ADV-2008-1102",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1744",
          "name" : "ADV-2008-1744",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41274",
          "name" : "krb5-rpclibrary-fdsetsize-bo(41274)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9209",
          "name" : "oval:org.mitre.oval:def:9209",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.2.2, and probably other versions before 1.3, when running on systems whose unistd.h does not define the FD_SETSIZE macro, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering a large number of open file descriptors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos_5:1.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-19T00:44Z",
    "lastModifiedDate" : "2020-01-21T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0949",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "informix_dynamic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.31.xd8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.31.xd9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.40.tc5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.40.uc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.40.uc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.40.uc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.40.uc5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.40.xd8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.40_xc7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.xc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.xc4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.00.xc7w1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.10.xc2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29272",
          "name" : "29272",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.informixmag.com/content/view/11143/27/",
          "name" : "http://www.informixmag.com/content/view/11143/27/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.informixmag.com/content/view/11144/27/",
          "name" : "http://www.informixmag.com/content/view/11144/27/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28198",
          "name" : "28198",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0860",
          "name" : "ADV-2008-0860",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/search.wss?rs=0&q=IC55224&apar=only",
          "name" : "IC55224",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/search.wss?rs=0&q=IC55225&apar=only",
          "name" : "IC55225",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41370",
          "name" : "ibm-ids-unspecified-privilege-escalation(41370)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in IBM Informix Dynamic Server (IDS) 7.x through 11.x allows remote attackers to gain privileges via a malformed connection request packet."
        }, {
          "lang" : "en",
          "value" : "IBM links require software support sign in to access information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:7.31.xd8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:7.31.xd9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.40.tc5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.40.uc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.40.uc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.40.uc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.40.uc5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.40.xd8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:9.40_xc7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:10.0.xc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:10.0.xc4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:10.00.xc7w1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:11.10.xc2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0951",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29458",
          "name" : "29458",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/889747",
          "name" : "VU#889747",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28360",
          "name" : "28360",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020446",
          "name" : "1020446",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0954/references",
          "name" : "ADV-2008-0954",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-038",
          "name" : "MS08-038",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41349",
          "name" : "vista-nodrivetypeautorun-weak-security(41349)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows Vista does not properly enforce the NoDriveTypeAutoRun registry value, which allows user-assisted remote attackers, and possibly physically proximate attackers, to execute arbitrary code by inserting a (1) CD-ROM device or (2) U3-enabled USB device containing a filesystem with an Autorun.inf file, and possibly other vectors related to (a) AutoRun and (b) AutoPlay actions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:business:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:enterprise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:home_basic:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:home_premium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:ultimate:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-24T22:44Z",
    "lastModifiedDate" : "2018-10-12T21:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0952",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "instant_support",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0.23",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/30516",
          "name" : "30516",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.csis.dk/dk/forside/CSIS-RI-0003.pdf",
          "name" : "http://www.csis.dk/dk/forside/CSIS-RI-0003.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/190939",
          "name" : "VU#190939",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29526",
          "name" : "29526",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29535",
          "name" : "29535",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020165",
          "name" : "1020165",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1740/references",
          "name" : "ADV-2008-1740",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www12.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01422264",
          "name" : "HPSBMA02326",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42834",
          "name" : "hp-instantsupport-append-file-overwrite(42834)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The AppendStringToFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to create files with arbitrary content via a full pathname in the first argument and the content in the second argument, a different vulnerability than CVE-2007-5608 and CVE-2008-0953."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:instant_support:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.0.23"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-06-04T20:32Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0953",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "instant_support",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0.23",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/30516",
          "name" : "30516",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.csis.dk/dk/forside/CSIS-RI-0003.pdf",
          "name" : "http://www.csis.dk/dk/forside/CSIS-RI-0003.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/998779",
          "name" : "VU#998779",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29526",
          "name" : "29526",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29533",
          "name" : "29533",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020165",
          "name" : "1020165",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1740/references",
          "name" : "ADV-2008-1740",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www12.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01422264",
          "name" : "SSRT071490",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42851",
          "name" : "hp-instantsupport-startapp-code-execution(42851)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The StartApp function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary programs via a .exe filename in the argument, a different vulnerability than CVE-2007-5608 and CVE-2008-0953."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:instant_support:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.0.23"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-06-04T20:32Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0955",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "creative",
            "product" : {
              "product_data" : [ {
                "product_name" : "creative_software_autoupdate_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/30403",
          "name" : "30403",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/501843",
          "name" : "VU#501843",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29391",
          "name" : "29391",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1668",
          "name" : "ADV-2008-1668",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42673",
          "name" : "creativesoftware-autoupdate-cachefolder-bo(42673)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5681",
          "name" : "5681",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote attackers to execute arbitrary code via a long CacheFolder property value."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:creative:creative_software_autoupdate_engine:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-05-29T16:32Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0956",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "backweb",
            "product" : {
              "product_data" : [ {
                "product_name" : "backweb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.1.86",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "logitech",
            "product" : {
              "product_data" : [ {
                "product_name" : "desktop_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.55",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://backweb.com/news_events/press_releases/051608.php",
          "name" : "http://backweb.com/news_events/press_releases/051608.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=121380194923597&w=2",
          "name" : "HPSBST02344",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30598",
          "name" : "30598",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30625",
          "name" : "30625",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/216153",
          "name" : "VU#216153",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29558",
          "name" : "29558",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-162B.html",
          "name" : "TA08-162B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1791",
          "name" : "ADV-2008-1791",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1792",
          "name" : "ADV-2008-1792",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-032",
          "name" : "MS08-032",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42991",
          "name" : "backweb-activex-liteinstactivator-bo(42991)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteInstActivator.dll in BackWeb before 8.1.1.87, as used in Logitech Desktop Manager (LDM) before 2.56, allow remote attackers to execute arbitrary code via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:backweb:backweb:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.1.1.86"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:logitech:desktop_manager:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.55"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-06-12T02:32Z",
    "lastModifiedDate" : "2018-10-12T21:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0957",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "photostockplus",
            "product" : {
              "product_data" : [ {
                "product_name" : "photostockplus_uploader_tool",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/30305",
          "name" : "30305",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/406937",
          "name" : "VU#406937",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29279",
          "name" : "29279",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1571",
          "name" : "ADV-2008-1571",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42534",
          "name" : "photostockplus-uploader-bo(42534)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in the PhotoStockPlus Uploader Tool ActiveX control (PSPUploader.ocx) allow remote attackers to execute arbitrary code via unspecified initialization parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:photostockplus:photostockplus_uploader_tool:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-05-20T17:20Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0958",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nctsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "nctaudioeditor_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/30414",
          "name" : "30414",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30451",
          "name" : "30451",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30452",
          "name" : "30452",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30453",
          "name" : "30453",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30454",
          "name" : "30454",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30458",
          "name" : "30458",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/656593",
          "name" : "VU#656593",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1669",
          "name" : "ADV-2008-1669",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42678",
          "name" : "nctaudioeditor-nctaudiograbber2-bo(42678)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioGrabber2 ActiveX control in NCTAudioGrabber2.dll allow remote attackers to execute arbitrary code via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nctsoft:nctaudioeditor_activex_control:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-05-29T16:32Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0959",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "alivemedia",
            "product" : {
              "product_data" : [ {
                "product_name" : "alive_mp3_wav_converter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.9.3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "online_media_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "nctaudioeditor_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "nctaudiostudio_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "orion_studios",
            "product" : {
              "product_data" : [ {
                "product_name" : "cinematicmp3",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "ussun",
            "product" : {
              "product_data" : [ {
                "product_name" : "power_audio_cd_burner",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.02",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "power_audio_cd_grabber",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/30395",
          "name" : "30395",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30415",
          "name" : "30415",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30418",
          "name" : "30418",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30419",
          "name" : "30419",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30421",
          "name" : "30421",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30445",
          "name" : "30445",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30451",
          "name" : "30451",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30452",
          "name" : "30452",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30453",
          "name" : "30453",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30454",
          "name" : "30454",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30456",
          "name" : "30456",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30457",
          "name" : "30457",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30458",
          "name" : "30458",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/669265",
          "name" : "VU#669265",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1669",
          "name" : "ADV-2008-1669",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42680",
          "name" : "nctaudiostudio-nctaudioinformation2-bo(42680)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioInformation2 ActiveX control in NCTAudioInformation2.dll, as used in (1) Power Audio CD Grabber 1.0, (2) Power Audio CD Burner 1.02, (3) CinematicMP3 1.4.0.0, (4) Alive MP3 WAV Converter 3.9.3.2, and possibly other products, allow remote attackers to execute arbitrary code via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alivemedia:alive_mp3_wav_converter:3.9.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:online_media_technologies:nctaudioeditor_activex_control:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:online_media_technologies:nctaudiostudio_activex_control:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:orion_studios:cinematicmp3:1.4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ussun:power_audio_cd_burner:1.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ussun:power_audio_cd_grabber:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-05-29T16:32Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0960",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "juniper",
            "product" : {
              "product_data" : [ {
                "product_name" : "session_and_resource_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "src_pe",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html",
          "name" : "APPLE-SA-2008-06-30",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.ingate.com/pipermail/productinfo/2008/000021.html",
          "name" : "[productinfo] 20080611 Ingate Firewall and SIParator affected by SNMPv3 vulnerability",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00000.html",
          "name" : "SUSE-SA:2008:039",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=127730470825399&w=2",
          "name" : "SSRT080082",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2008-0528.html",
          "name" : "RHSA-2008:0528",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30574",
          "name" : "30574",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30596",
          "name" : "30596",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30612",
          "name" : "30612",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30615",
          "name" : "30615",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30626",
          "name" : "30626",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30647",
          "name" : "30647",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30648",
          "name" : "30648",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30665",
          "name" : "30665",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30802",
          "name" : "30802",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31334",
          "name" : "31334",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31351",
          "name" : "31351",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31467",
          "name" : "31467",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31568",
          "name" : "31568",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/32664",
          "name" : "32664",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/33003",
          "name" : "33003",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/35463",
          "name" : "35463",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200808-02.xml",
          "name" : "GLSA-200808-02",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3933",
          "name" : "3933",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/forum/forum.php?forum_id=833770",
          "name" : "http://sourceforge.net/forum/forum.php?forum_id=833770",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/tracker/index.php?func=detail&aid=1989089&group_id=12694&atid=456380",
          "name" : "http://sourceforge.net/tracker/index.php?func=detail&aid=1989089&group_id=12694&atid=456380",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238865-1",
          "name" : "238865",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT2163",
          "name" : "http://support.apple.com/kb/HT2163",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2008-282.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2008-282.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20080610-snmpv3.shtml",
          "name" : "20080610 SNMP Version 3 Authentication Vulnerabilities",
          "refsource" : "CISCO",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1663",
          "name" : "DSA-1663",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/878044",
          "name" : "VU#878044",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/CTAR-7FBS8Q",
          "name" : "http://www.kb.cert.org/vuls/id/CTAR-7FBS8Q",
          "refsource" : "CONFIRM",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/MIMG-7ETS5Z",
          "name" : "http://www.kb.cert.org/vuls/id/MIMG-7ETS5Z",
          "refsource" : "CONFIRM",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/MIMG-7ETS87",
          "name" : "http://www.kb.cert.org/vuls/id/MIMG-7ETS87",
          "refsource" : "CONFIRM",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2008:118",
          "name" : "MDVSA-2008:118",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.ocert.org/advisories/ocert-2008-006.html",
          "name" : "http://www.ocert.org/advisories/ocert-2008-006.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2008/06/09/1",
          "name" : "[oss-security] 20080609 [oCERT-2008-006] multiple SNMP implementations HMAC authentication spoofing",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0529.html",
          "name" : "RHSA-2008:0529",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/493218/100/0/threaded",
          "name" : "20080609 [oCERT-2008-006] multiple SNMP implementations HMAC authentication spoofing",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/497962/100/0/threaded",
          "name" : "20081031 VMSA-2008-0017 Updated ESX packages for libxml2, ucd-snmp, libtiff",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29623",
          "name" : "29623",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020218",
          "name" : "1020218",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-685-1",
          "name" : "USN-685-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-162A.html",
          "name" : "TA08-162A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vmware.com/security/advisories/VMSA-2008-0013.html",
          "name" : "http://www.vmware.com/security/advisories/VMSA-2008-0013.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/security/advisories/VMSA-2008-0017.html",
          "name" : "http://www.vmware.com/security/advisories/VMSA-2008-0017.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1787/references",
          "name" : "ADV-2008-1787",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1788/references",
          "name" : "ADV-2008-1788",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1797/references",
          "name" : "ADV-2008-1797",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1800/references",
          "name" : "ADV-2008-1800",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1801/references",
          "name" : "ADV-2008-1801",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1836/references",
          "name" : "ADV-2008-1836",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1981/references",
          "name" : "ADV-2008-1981",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2361",
          "name" : "ADV-2008-2361",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2971",
          "name" : "ADV-2008-2971",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2009/1612",
          "name" : "ADV-2009-1612",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=447974",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=447974",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10820",
          "name" : "oval:org.mitre.oval:def:10820",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5785",
          "name" : "oval:org.mitre.oval:def:5785",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6414",
          "name" : "oval:org.mitre.oval:def:6414",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5790",
          "name" : "5790",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00363.html",
          "name" : "FEDORA-2008-5215",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00380.html",
          "name" : "FEDORA-2008-5224",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00459.html",
          "name" : "FEDORA-2008-5218",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:catos:7.1.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:catos:7.3.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:catos:7.4.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:catos:8.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.0:s:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.0:sy:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.1:e:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.2:ewa:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.2:jk:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.2:sb:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.2:sg:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.2:sga:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.2:sra:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.2:srb:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.2:src:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.2:sxb:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.2:sxd:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.2:sxf:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.2:zl:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.2:zy:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:b:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:ja:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:jeb:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:jk:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:jl:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:jx:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:t:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:xa:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:xg:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:xi:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:xk:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:xr:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:yf:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:yi:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:yt:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.3:yx:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.4:t:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.4:xa:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.4:xc:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.4:xd:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.4:xe:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.4:xj:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:cisco_ios:12.4:xw:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:ios:10.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:ios:11.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:ios:11.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:ios:11.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:ios_xr:2.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:ios_xr:3.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:ios_xr:3.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:ios_xr:3.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:ios_xr:3.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:ios_xr:3.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:ios_xr:3.6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:ios_xr:3.7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:nx_os:4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:nx_os:4.0.1:a:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:cisco:nx_os:4.0.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ecos_sourceware:ecos:1.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ecos_sourceware:ecos:1.2.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ecos_sourceware:ecos:1.3.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ecos_sourceware:ecos:2.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ecos_sourceware:ecos:2.0:b1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.0.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.0.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.0.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.0.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.0.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.0.6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.0.7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.0.8:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.0.9:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.1.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.1.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.3.0.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:net-snmp:net_snmp:5.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:unkown:x86:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.10:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:ace_10_6504_bundle_with_4_gbps_throughput:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:ace_10_6509_bundle_with_8_gbps_throughput:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:ace_10_service_module:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:ace_20_6504_bundle_with__4gbps_throughput:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:ace_20_6509_bundle_with_8gbps_throughput:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:ace_20_service_module:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:ace_4710:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:ace_xml_gateway:5.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:ace_xml_gateway:6.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:mds_9120:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:mds_9124:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:mds_9134:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:cisco:mds_9140:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:2.2.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:2.2.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:2.2.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:2.3.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:2.4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:2.4.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:2.5.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:2.6.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:2.6.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:3.0.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:3.1.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:3.1.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:3.1.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:3.1.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:3.2.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:3.2.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:3.2.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:3.3.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:4.1.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:4.1.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:4.2.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:4.2.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:4.2.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:4.3.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:4.4.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:4.4.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:4.5.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:4.5.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:4.6.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:4.6.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_firewall:4.6.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:2.2.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:2.2.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:2.2.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:2.3.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:2.4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:2.4.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:2.5.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:2.6.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:2.6.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:3.0.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:3.1.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:3.1.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:3.1.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:3.1.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:3.2.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:3.2.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:3.2.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:3.3.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:4.1.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:4.1.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:4.2.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:4.2.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:4.2.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:4.3.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:4.3.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:4.4.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:4.4.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:4.5.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:4.5.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:4.6.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:4.6.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:ingate:ingate_siparator:4.6.2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:juniper:session_and_resource_control:1.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:juniper:session_and_resource_control:2.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:juniper:src_pe:1.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:juniper:src_pe:2.0:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-06-10T18:32Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0961",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "emc",
            "product" : {
              "product_data" : [ {
                "product_name" : "diskxtender",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.20.060",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=683",
          "name" : "20080410 EMC DiskXtender Authentication Bypass Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29778",
          "name" : "29778",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/44419",
          "name" : "44419",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28727",
          "name" : "28727",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019827",
          "name" : "1019827",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1198/references",
          "name" : "ADV-2008-1198",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41772",
          "name" : "emc-diskxtender-unauthorized-access(41772)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "EMV DiskXtender 6.20.060 has a hard-coded login and password, which allows remote attackers to bypass authentication via the RPC interface."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:emc:diskxtender:6.20.060:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-14T16:05Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0962",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "emc",
            "product" : {
              "product_data" : [ {
                "product_name" : "diskxtender",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.20.060",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=684",
          "name" : "20080410 EMC DiskXtender File System Manager Stack Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29778",
          "name" : "29778",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/44418",
          "name" : "44418",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28728",
          "name" : "28728",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019828",
          "name" : "1019828",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1198/references",
          "name" : "ADV-2008-1198",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41774",
          "name" : "emc-diskxtender-filesystemmanager-bo(41774)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the File System Manager for EMC DiskXtender 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted request to the RPC interface."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:emc:diskxtender:6.20.060:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-14T16:05Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0963",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "emc",
            "product" : {
              "product_data" : [ {
                "product_name" : "diskxtender",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.20.060",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=685",
          "name" : "20080410 EMC DiskXtender MediaStor Format String Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29778",
          "name" : "29778",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/44417",
          "name" : "44417",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28727",
          "name" : "28727",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28729",
          "name" : "28729",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019829",
          "name" : "1019829",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1198/references",
          "name" : "ADV-2008-1198",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41773",
          "name" : "emc-diskxtender-mediastor-format-string(41773)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in EMC DiskXtender MediaStor 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted message to the RPC interface."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:emc:diskxtender:6.20.060:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-04-14T16:05Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0964",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "opensolaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_88",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_89",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_91",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_92",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_95",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sunos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=734",
          "name" : "20080804 Solaris snoop SMB Decoding Multiple Stack Buffer Overflow Vulnerabilities",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31386",
          "name" : "31386",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31535",
          "name" : "31535",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-240101-1",
          "name" : "240101",
          "refsource" : "SUNALERT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2008-355.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2008-355.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=766935",
          "name" : "http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=766935",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/30556",
          "name" : "30556",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020633",
          "name" : "1020633",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2311",
          "name" : "ADV-2008-2311",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/44222",
          "name" : "solaris-snoop1m-bo(44222)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5318",
          "name" : "oval:org.mitre.oval:def:5318",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/6328",
          "name" : "6328",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via a crafted SMB packet."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:*:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:*:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_64:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_88:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_89:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_91:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_92:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "build_snv_95"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:8:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:8:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-08-08T18:41Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0965",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "opensolaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_88",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_89",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_91",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_92",
                    "version_affected" : "="
                  }, {
                    "version_value" : "build_snv_95",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sunos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=735",
          "name" : "20080804 Solaris snoop SMB Decoding Multiple Format String Vulnerabilities",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31386",
          "name" : "31386",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31535",
          "name" : "31535",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-240101-1",
          "name" : "240101",
          "refsource" : "SUNALERT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2008-355.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2008-355.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=766935",
          "name" : "http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=766935",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/30556",
          "name" : "30556",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020633",
          "name" : "1020633",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2311",
          "name" : "ADV-2008-2311",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/44222",
          "name" : "sun-solaris-snoop1m-command-execution(44222)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/44415",
          "name" : "solaris-snoop1m-format-string(44415)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5742",
          "name" : "oval:org.mitre.oval:def:5742",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via format string specifiers in an SMB packet."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:*:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:*:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_64:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_88:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_89:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_91:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:build_snv_92:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:opensolaris:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "build_snv_95"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:8:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:8:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-08-08T18:41Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0967",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vmware",
            "product" : {
              "product_data" : [ {
                "product_name" : "esx_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "esxi",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "vmware_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "vmware_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "esx",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=713",
          "name" : "20080604 VMware Multiple Products vmware-authd Untrusted Library Loading Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30556",
          "name" : "30556",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-201209-25.xml",
          "name" : "GLSA-201209-25",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3922",
          "name" : "3922",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1020198",
          "name" : "1020198",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/493080/100/0/threaded",
          "name" : "20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29557",
          "name" : "29557",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/security/advisories/VMSA-2008-0009.html",
          "name" : "http://www.vmware.com/security/advisories/VMSA-2008-0009.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1744",
          "name" : "ADV-2008-1744",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42878",
          "name" : "vmware-vmwareauthd-privilege-escalation(42878)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4768",
          "name" : "oval:org.mitre.oval:def:4768",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5583",
          "name" : "oval:org.mitre.oval:def:5583",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges via a library path option in a configuration file."
        }, {
          "lang" : "en",
          "value" : "Per: http://cwe.mitre.org/data/definitions/426.html \r\n'CWE-426: Untrusted Search Path'"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:esx_server:2.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:esx_server:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:esx_server:3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:esx_server:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:esx_server:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:esxi:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:server:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_server:1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_server:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_server:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_server:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_server:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_workstation:5.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_workstation:5.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_workstation:5.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_workstation:5.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_workstation:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_workstation:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_workstation:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:5.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:5.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:5.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:vmware:esx:3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:vmware:esx:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:vmware:esx:3.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-06-05T20:32Z",
    "lastModifiedDate" : "2018-10-30T16:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0971",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "barracuda_networks",
            "product" : {
              "product_data" : [ {
                "product_name" : "barracuda_im_firewall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.01.008",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "barracuda_load_balancer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2.006",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "barracuda_message_archiver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.0.010",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "barracuda_spam_firewall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5.11.020",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "barracuda_web_filter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.0.038",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dcsl.ul.ie/advisories/03.htm",
          "name" : "http://dcsl.ul.ie/advisories/03.htm",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/33164",
          "name" : "33164",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/4792",
          "name" : "4792",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1021454",
          "name" : "1021454",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.barracudanetworks.com/ns/support/tech_alert.php",
          "name" : "http://www.barracudanetworks.com/ns/support/tech_alert.php",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/50709",
          "name" : "50709",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/499294/100/0/threaded",
          "name" : "20081216 CVE-2008-0971 - Barracuda Networks products Multiple Cross-Site Scripting Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Barracuda Spam Firewall (BSF) before 3.5.12.007, Message Archiver before 1.2.1.002, Web Filter before 3.3.0.052, IM Firewall before 3.1.01.017, and Load Balancer before 2.3.024 allow remote attackers to inject arbitrary web script or HTML via (1) the Policy Name field in Search Based Retention Policy in Message Archiver; unspecified parameters in the (2) IP Configuration, (3) Administration, (4) Journal Accounts, (5) Retention Policy, and (6) GroupWise Sync components in Message Archiver; (7) input to search operations in Web Filter; and (8) input used in error messages and (9) hidden INPUT elements in (a) Spam Firewall, (b) IM Firewall, and (c) Web Filter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:barracuda_networks:barracuda_im_firewall:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0.01.008"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:barracuda_networks:barracuda_load_balancer:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.2.006"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:barracuda_networks:barracuda_message_archiver:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.0.010"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:barracuda_networks:barracuda_spam_firewall:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.5.11.020"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:barracuda_networks:barracuda_web_filter:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.3.0.038"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-12-19T17:30Z",
    "lastModifiedDate" : "2018-10-15T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0973",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "double-take_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "double-take",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0.2865",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://aluigi.org/poc/doubletakedown.zip",
          "name" : "http://aluigi.org/poc/doubletakedown.zip",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29075",
          "name" : "29075",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3698",
          "name" : "3698",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488632/100/0/threaded",
          "name" : "20080222 Multiple vulnerabilities in Double-Take 5.0.0.2865",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27951",
          "name" : "27951",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0666",
          "name" : "ADV-2008-0666",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Double-Take (aka HP StorageWorks Storage Mirroring) 4.5.0.1629, and other 4.5.0.x versions, allows remote attackers to have an unknown impact via a packet with a long string in the username field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:double-take_software:double-take:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:double-take_software:double-take:5.0.0.2865:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0974",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "double-take_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "double-take",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0.2865",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "storageworks_double-take",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.0.2865",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://aluigi.org/poc/doubletakedown.zip",
          "name" : "http://aluigi.org/poc/doubletakedown.zip",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29075",
          "name" : "29075",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3698",
          "name" : "3698",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488632/100/0/threaded",
          "name" : "20080222 Multiple vulnerabilities in Double-Take 5.0.0.2865",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27951",
          "name" : "27951",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0666",
          "name" : "ADV-2008-0666",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (daemon termination) via (1) a large vector<T> value, which raises a \"vector<T> too long\" exception; or (2) a certain packet that raises an ospace/time/src\\date.cpp exception."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:double-take_software:double-take:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:double-take_software:double-take:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0.0.2865"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:storageworks_double-take:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0.0.2865"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0975",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "double-take_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "double-take",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0.2865",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://aluigi.org/poc/doubletakedown.zip",
          "name" : "http://aluigi.org/poc/doubletakedown.zip",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29075",
          "name" : "29075",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3698",
          "name" : "3698",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488632/100/0/threaded",
          "name" : "20080222 Multiple vulnerabilities in Double-Take 5.0.0.2865",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27951",
          "name" : "27951",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0666",
          "name" : "ADV-2008-0666",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (CPU consumption) via a -1 value in the field that specifies the size of the vector<T> value."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:double-take_software:double-take:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:double-take_software:double-take:5.0.0.2865:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0976",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "double-take_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "double-take",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0.2865",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "storageworks_double-take",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.0.2865",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://aluigi.org/poc/doubletakedown.zip",
          "name" : "http://aluigi.org/poc/doubletakedown.zip",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29075",
          "name" : "29075",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3698",
          "name" : "3698",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488632/100/0/threaded",
          "name" : "20080222 Multiple vulnerabilities in Double-Take 5.0.0.2865",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27951",
          "name" : "27951",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0666",
          "name" : "ADV-2008-0666",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed packet, as demonstrated by a packet of type (1) 0x2722 or (2) 0x272a."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:double-take_software:double-take:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:double-take_software:double-take:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0.0.2865"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:storageworks_double-take:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0.0.2865"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0977",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "double-take_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "double-take",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0.2865",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://aluigi.org/poc/doubletakedown.zip",
          "name" : "http://aluigi.org/poc/doubletakedown.zip",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29075",
          "name" : "29075",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3698",
          "name" : "3698",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488632/100/0/threaded",
          "name" : "20080222 Multiple vulnerabilities in Double-Take 5.0.0.2865",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27951",
          "name" : "27951",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0666",
          "name" : "ADV-2008-0666",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (daemon crash) via a certain long packet that triggers an attempt to allocate a large amount of memory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:double-take_software:double-take:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:double-take_software:double-take:5.0.0.2865:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0978",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "double-take_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "double-take",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0.2865",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://aluigi.org/poc/doubletakedown.zip",
          "name" : "http://aluigi.org/poc/doubletakedown.zip",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29075",
          "name" : "29075",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3698",
          "name" : "3698",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488632/100/0/threaded",
          "name" : "20080222 Multiple vulnerabilities in Double-Take 5.0.0.2865",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27951",
          "name" : "27951",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0666",
          "name" : "ADV-2008-0666",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to obtain sensitive information via a packet of type (1) 0x2728, which provides operating system and path information; (2) 0x274e, which lists Ethernet adapters; (3) 0x2726, which provides filesystem information; (4) 0x274f, which specifies the printer driver; or (5) 0x2757, which provides recent log entries."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:double-take_software:double-take:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:double-take_software:double-take:5.0.0.2865:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0979",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "double-take_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "double-take",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0.2865",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "storageworks_double-take",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.0.2865",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://aluigi.org/poc/doubletakedown.zip",
          "name" : "http://aluigi.org/poc/doubletakedown.zip",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29075",
          "name" : "29075",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3698",
          "name" : "3698",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488632/100/0/threaded",
          "name" : "20080222 Multiple vulnerabilities in Double-Take 5.0.0.2865",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27951",
          "name" : "27951",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0666",
          "name" : "ADV-2008-0666",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack consumption vulnerability in Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (daemon crash) via a certain packet that triggers the recursive calling of a function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:double-take_software:double-take:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:double-take_software:double-take:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0.0.2865"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:storageworks_double-take:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0.0.2865"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0980",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "spyce",
            "product" : {
              "product_data" : [ {
                "product_name" : "spyce",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3699",
          "name" : "3699",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.procheckup.com/Vulnerability_PR08-01.php",
          "name" : "http://www.procheckup.com/Vulnerability_PR08-01.php",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488336/100/0/threaded",
          "name" : "20080219 PR08-01: Several XSS, a cross-domain redirect and a webroot disclosure on Spyce - Python Server Pages (PSP)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27898",
          "name" : "27898",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the url or type parameter to docs/examples/redirect.spy; (2) the x parameter to docs/examples/handlervalidate.spy; (3) the name parameter to spyce/examples/request.spy; (4) the Name parameter to spyce/examples/getpost.spy; (5) the mytextarea parameter, the mypass parameter, or an empty parameter to spyce/examples/formtag.spy; (6) the newline parameter to the default URI under demos/chat/; (7) the text1 parameter to docs/examples/formintro.spy; or (8) the mytext or mydate parameter to docs/examples/formtag.spy."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spyce:spyce:2.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-25T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0981",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "spyce",
            "product" : {
              "product_data" : [ {
                "product_name" : "spyce",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3699",
          "name" : "3699",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.procheckup.com/Vulnerability_PR08-01.php",
          "name" : "http://www.procheckup.com/Vulnerability_PR08-01.php",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488336/100/0/threaded",
          "name" : "20080219 PR08-01: Several XSS, a cross-domain redirect and a webroot disclosure on Spyce - Python Server Pages (PSP)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27898",
          "name" : "27898",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Open redirect vulnerability in spyce/examples/redirect.spy in Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spyce:spyce:2.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-25T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0982",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "spyce",
            "product" : {
              "product_data" : [ {
                "product_name" : "spyce",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3699",
          "name" : "3699",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.procheckup.com/Vulnerability_PR08-01.php",
          "name" : "http://www.procheckup.com/Vulnerability_PR08-01.php",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488336/100/0/threaded",
          "name" : "20080219 PR08-01: Several XSS, a cross-domain redirect and a webroot disclosure on Spyce - Python Server Pages (PSP)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27898",
          "name" : "27898",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to obtain sensitive information via a direct request for spyce/examples/automaton.spy, which reveals the path in an error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spyce:spyce:2.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-25T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0983",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lighttpd",
            "product" : {
              "product_data" : [ {
                "product_name" : "lighttpd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.18",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html",
          "name" : "SUSE-SR:2008:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29066",
          "name" : "29066",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29166",
          "name" : "29166",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29209",
          "name" : "29209",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29268",
          "name" : "29268",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29622",
          "name" : "29622",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31104",
          "name" : "31104",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200803-10.xml",
          "name" : "GLSA-200803-10",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://trac.lighttpd.net/trac/ticket/1562",
          "name" : "http://trac.lighttpd.net/trac/ticket/1562",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2008-0084",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2008-0084",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1609",
          "name" : "DSA-1609",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488926/100/0/threaded",
          "name" : "20080228 rPSA-2008-0084-1 lighttpd",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27943",
          "name" : "27943",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0659/references",
          "name" : "ADV-2008-0659",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-2284",
          "name" : "https://issues.rpath.com/browse/RPL-2284",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00162.html",
          "name" : "FEDORA-2008-2262",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00180.html",
          "name" : "FEDORA-2008-2278",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.18:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-26T18:44Z",
    "lastModifiedDate" : "2018-10-15T22:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0984",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "miro",
            "product" : {
              "product_data" : [ {
                "product_name" : "miro_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "videolan",
            "product" : {
              "product_data" : [ {
                "product_name" : "vlc_media_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.6d",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060481.html",
          "name" : "20080227 CORE-2008-0130: VLC media player chunk context validation error",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29122",
          "name" : "29122",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29153",
          "name" : "29153",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29284",
          "name" : "29284",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29766",
          "name" : "29766",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.coresecurity.com/?action=item&id=2147",
          "name" : "http://www.coresecurity.com/?action=item&id=2147",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1543",
          "name" : "DSA-1543",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200803-13.xml",
          "name" : "GLSA-200803-13",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488841/100/0/threaded",
          "name" : "20080227 CORE-2008-0130: VLC media player chunk context validation error",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28007",
          "name" : "28007",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019510",
          "name" : "1019510",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.videolan.org/security/sa0802.html",
          "name" : "http://www.videolan.org/security/sa0802.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0682",
          "name" : "ADV-2008-0682",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:miro:miro_player:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.8.6d"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-26T19:44Z",
    "lastModifiedDate" : "2018-10-15T22:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0985",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "google",
            "product" : {
              "product_data" : [ {
                "product_name" : "android_sdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "m3-rc37a",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://android-developers.blogspot.com/2008/03/android-sdk-update-m5-rc15-released.html",
          "name" : "http://android-developers.blogspot.com/2008/03/android-sdk-update-m5-rc15-released.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3727",
          "name" : "3727",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.coresecurity.com/?action=item&id=2148",
          "name" : "http://www.coresecurity.com/?action=item&id=2148",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489135/100/0/threaded",
          "name" : "20080304 CORE-2008-0124: Multiple vulnerabilities in Google's Android SDK",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28005",
          "name" : "28005",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40998",
          "name" : "androidsdk-gifimagedecoderondecode-bo(40998)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the GIF library in the WebKit framework for Google Android SDK m3-rc37a and earlier allows remote attackers to execute arbitrary code via a crafted GIF file whose logical screen height and width are different than the actual height and width."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:google:android_sdk:m3-rc37a:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-06T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0986",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "google",
            "product" : {
              "product_data" : [ {
                "product_name" : "android_sdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "m3-rc37a",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "m5-rc14",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://android-developers.blogspot.com/2008/03/android-sdk-update-m5-rc15-released.html",
          "name" : "http://android-developers.blogspot.com/2008/03/android-sdk-update-m5-rc15-released.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3727",
          "name" : "3727",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.coresecurity.com/?action=item&id=2148",
          "name" : "http://www.coresecurity.com/?action=item&id=2148",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489135/100/0/threaded",
          "name" : "20080304 CORE-2008-0124: Multiple vulnerabilities in Google's Android SDK",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28006",
          "name" : "28006",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40999",
          "name" : "androidsdk-bmpreadfromstream-int-overflow(40999)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier, and m5-rc14, allows remote attackers to execute arbitrary code via a crafted BMP file with a header containing a negative offset field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:google:android_sdk:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "m3-rc37a"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:google:android_sdk:m5-rc14:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-06T00:44Z",
    "lastModifiedDate" : "2018-10-15T22:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0987",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "aperture",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "iphoto",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00003.html",
          "name" : "APPLE-SA-2008-03-20",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29469",
          "name" : "29469",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://support.apple.com/kb/HT1232",
          "name" : "http://support.apple.com/kb/HT1232",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28363",
          "name" : "28363",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019659",
          "name" : "1019659",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019683",
          "name" : "1019683",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019684",
          "name" : "1019684",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0957/references",
          "name" : "ADV-2008-0957",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41294",
          "name" : "macos-imageraw-bo(41294)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Image Raw in Apple Mac OS X 10.5.2, and Digital Camera RAW Compatibility before Update 2.0 for Aperture 2 and iPhoto 7.1.2, allows remote attackers to execute arbitrary code via a crafted Adobe Digital Negative (DNG) image."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:aperture:2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:iphoto:7.1.2:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0988",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28374",
          "name" : "28374",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019661",
          "name" : "1019661",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Off-by-one error in the Libsystem strnstr API in libc on Apple Mac OS X 10.4.11 allows context-dependent attackers to cause a denial of service (crash) via crafted arguments that trigger a buffer over-read."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0989",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28339",
          "name" : "28339",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019662",
          "name" : "1019662",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41292",
          "name" : "macos-mdnsresponderhelper-format-string(41292)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in mDNSResponderHelper in Apple Mac OS X 10.5.2 allows local users to execute arbitrary code via format string specifiers in the local hostname."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0990",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28345",
          "name" : "28345",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019663",
          "name" : "1019663",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41289",
          "name" : "macos-notifyd-dos(41289)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "notifyd in Apple Mac OS X 10.4.11 does not verify that Mach port death notifications have originated from the kernel, which allows local users to cause a denial of service via spoofed death notifications that prevent other applications from receiving notifications."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0992",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28365",
          "name" : "28365",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019673",
          "name" : "1019673",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41288",
          "name" : "macos-pax-code-execution(41288)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Array index error in pax in Apple Mac OS X 10.5.2 allows context-dependent attackers to execute arbitrary code via an archive with a crafted length value."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0993",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "podcast_producer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28372",
          "name" : "28372",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019664",
          "name" : "1019664",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Podcast Capture in Podcast Producer for Apple Mac OS X 10.5.2 invokes a subtask with passwords in command line arguments, which allows local users to read the passwords via process listings."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:podcast_producer:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2013-08-27T05:56Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0994",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28386",
          "name" : "28386",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019665",
          "name" : "1019665",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41276",
          "name" : "macos-preview-weak-encryption(41276)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Preview in Apple Mac OS X 10.5.2 uses 40-bit RC4 when saving a PDF file with encryption, which makes it easier for attackers to decrypt the file via brute force methods."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0995",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28387",
          "name" : "28387",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019667",
          "name" : "1019667",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41287",
          "name" : "macos-printing-weak-encryption(41287)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Printing component in Apple Mac OS X 10.5.2 uses 40-bit RC4 when printing to an encrypted PDF file, which makes it easier for attackers to decrypt the file via brute force methods."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0996",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-255"
          }, {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28344",
          "name" : "28344",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019667",
          "name" : "1019667",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41284",
          "name" : "macos-printqueue-information-disclosure(41284)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Printing component in Apple Mac OS X 10.5.2 might save authentication credentials to disk when starting a job on an authenticated print queue, which might allow local users to obtain the credentials."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.1,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0997",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28364",
          "name" : "28364",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019648",
          "name" : "1019648",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41282",
          "name" : "macos-appkit-ppd-bo(41282)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows user-assisted remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted PostScript Printer Description (PPD) file that is not properly handled when querying a network printer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-18T22:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0998",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28385",
          "name" : "28385",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019674",
          "name" : "1019674",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41281",
          "name" : "macos-netcfgtool-code-execution(41281)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in NetCfgTool in the System Configuration component in Apple Mac OS X 10.4.11 and 10.5.2 allows local users to bypass authorization and execute arbitrary code via crafted distributed objects."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-0999",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28304",
          "name" : "28304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28389",
          "name" : "28389",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019669",
          "name" : "1019669",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41280",
          "name" : "macos-udf-dos(41280)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Apple Mac OS X 10.5.2 allows user-assisted attackers to cause a denial of service (crash) via a crafted Universal Disc Format (UDF) disk image, which triggers a NULL pointer dereference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1000",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.coresecurity.com/index.php5?module=ContentMod&action=item&id=2189",
          "name" : "http://www.coresecurity.com/index.php5?module=ContentMod&action=item&id=2189",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/489786/100/0/threaded",
          "name" : "20080318 CORE-2008-0123: Leopard Server Remote Path Traversal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28278",
          "name" : "28278",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019660",
          "name" : "1019660",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41278",
          "name" : "macos-contentserver-directory-traversal(41278)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in ContentServer.py in the Wiki Server in Apple Mac OS X 10.5.2 (aka Leopard) allows remote authenticated users to write arbitrary files via \"..\" sequences in file attachments."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 8.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 6.8,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-18T23:44Z",
    "lastModifiedDate" : "2018-10-15T22:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1001",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307563",
          "name" : "http://docs.info.apple.com/article.html?artnum=307563",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28290",
          "name" : "28290",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28321",
          "name" : "28321",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019653",
          "name" : "1019653",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0920/references",
          "name" : "ADV-2008-0920",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41333",
          "name" : "safari-errorpage-xss(41333)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1, when running on Windows XP or Vista, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that is not properly handled in the error page."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.4:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-19T00:44Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1002",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307563",
          "name" : "http://docs.info.apple.com/article.html?artnum=307563",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29393",
          "name" : "29393",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/766019",
          "name" : "VU#766019",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28290",
          "name" : "28290",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28328",
          "name" : "28328",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019653",
          "name" : "1019653",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0920/references",
          "name" : "ADV-2008-0920",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41335",
          "name" : "safari-javascripturls-security-bypass(41335)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1 allows remote attackers to inject arbitrary web script or HTML via a crafted javascript: URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-19T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1003",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307563",
          "name" : "http://docs.info.apple.com/article.html?artnum=307563",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29393",
          "name" : "29393",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28290",
          "name" : "28290",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28330",
          "name" : "28330",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019653",
          "name" : "1019653",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0920/references",
          "name" : "ADV-2008-0920",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41334",
          "name" : "safari-documentdomain-security-bypass(41334)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to sites that set the document.domain property or have the same document.domain."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-19T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1004",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307563",
          "name" : "http://docs.info.apple.com/article.html?artnum=307563",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29393",
          "name" : "29393",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28290",
          "name" : "28290",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28347",
          "name" : "28347",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019653",
          "name" : "1019653",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0920/references",
          "name" : "ADV-2008-0920",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41331",
          "name" : "safari-webinspector-security-bypass(41331)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the Web Inspector."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-19T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1005",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307563",
          "name" : "http://docs.info.apple.com/article.html?artnum=307563",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29393",
          "name" : "29393",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28290",
          "name" : "28290",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28326",
          "name" : "28326",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019656",
          "name" : "1019656",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0920/references",
          "name" : "ADV-2008-0920",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41329",
          "name" : "safari-webcore-weak-security(41329)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WebCore, as used in Apple Safari before 3.1, does not properly mask the password field when reverse conversion is used with the Kotoeri input method, which allows physically proximate attackers to read the password."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-19T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1006",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307563",
          "name" : "http://docs.info.apple.com/article.html?artnum=307563",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29393",
          "name" : "29393",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28290",
          "name" : "28290",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28332",
          "name" : "28332",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019653",
          "name" : "1019653",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0920/references",
          "name" : "ADV-2008-0920",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41326",
          "name" : "safari-windowopen-security-bypass(41326)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML by using the window.open function to change the security context of a web page."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-19T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1007",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307563",
          "name" : "http://docs.info.apple.com/article.html?artnum=307563",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29393",
          "name" : "29393",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28290",
          "name" : "28290",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28335",
          "name" : "28335",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019653",
          "name" : "1019653",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0920/references",
          "name" : "ADV-2008-0920",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41324",
          "name" : "safari-navigation-policy-security-bypass(41324)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java applets, which allows remote attackers to conduct cross-site scripting (XSS) attacks."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-19T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1008",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307563",
          "name" : "http://docs.info.apple.com/article.html?artnum=307563",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29393",
          "name" : "29393",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28290",
          "name" : "28290",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28336",
          "name" : "28336",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019653",
          "name" : "1019653",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0920/references",
          "name" : "ADV-2008-0920",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41323",
          "name" : "safari-documentdomain-xss(41323)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via the document.domain property."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-19T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1009",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307563",
          "name" : "http://docs.info.apple.com/article.html?artnum=307563",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29393",
          "name" : "29393",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28290",
          "name" : "28290",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28337",
          "name" : "28337",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019653",
          "name" : "1019653",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0920/references",
          "name" : "ADV-2008-0920",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41322",
          "name" : "safari-historyobject-security-bypass(41322)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary JavaScript by modifying the history object."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-19T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1010",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307563",
          "name" : "http://docs.info.apple.com/article.html?artnum=307563",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29393",
          "name" : "29393",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29924",
          "name" : "29924",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28290",
          "name" : "28290",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28338",
          "name" : "28338",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019654",
          "name" : "1019654",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0920/references",
          "name" : "ADV-2008-0920",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41321",
          "name" : "safari-webkit-bo(41321)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00402.html",
          "name" : "FEDORA-2008-3229",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in WebKit, as used in Apple Safari before 3.1, allows remote attackers to execute arbitrary code via crafted regular expressions in JavaScript."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-19T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1011",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307563",
          "name" : "http://docs.info.apple.com/article.html?artnum=307563",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/29393",
          "name" : "29393",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29924",
          "name" : "29924",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28290",
          "name" : "28290",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28342",
          "name" : "28342",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019653",
          "name" : "1019653",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-079A.html",
          "name" : "TA08-079A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0920/references",
          "name" : "ADV-2008-0920",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41320",
          "name" : "safari-webkitcomponent-security-bypass(41320)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00402.html",
          "name" : "FEDORA-2008-3229",
          "refsource" : "FEDORA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via a frame that calls a method instance in another frame."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-03-19T00:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1012",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "apple_airport_extreme_base_station",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00002.html",
          "name" : "APPLE-SA-2008-03-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29447",
          "name" : "29447",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT1226",
          "name" : "http://support.apple.com/kb/HT1226",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28348",
          "name" : "28348",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019678",
          "name" : "1019678",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0955/references",
          "name" : "ADV-2008-0955",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41325",
          "name" : "airport-extremebasestation-afp-dos(41325)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Apple AirPort Extreme Base Station Firmware 7.3.1 allows remote attackers to cause a denial of service (file sharing hang) via a crafted AFP request, related to \"input validation.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:apple_airport_extreme_base_station:*:*:7.3.1_firmware:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-03-20T10:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1013",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29650",
          "name" : "29650",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019757",
          "name" : "1019757",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT1241",
          "name" : "http://support.apple.com/kb/HT1241",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28583",
          "name" : "28583",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-094A.html",
          "name" : "TA08-094A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1078",
          "name" : "ADV-2008-1078",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41601",
          "name" : "quicktime-qtjava-code-execution(41601)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Apple QuickTime before 7.4.5 enables deserialization of QTJava objects by untrusted Java applets, which allows remote attackers to execute arbitrary code via a crafted applet."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.4.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-04T17:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1014",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          }, {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29650",
          "name" : "29650",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019758",
          "name" : "1019758",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT1241",
          "name" : "http://support.apple.com/kb/HT1241",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28583",
          "name" : "28583",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-094A.html",
          "name" : "TA08-094A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1078",
          "name" : "ADV-2008-1078",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41602",
          "name" : "quicktime-moviefiles-information-disclosure(41602)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Apple QuickTime before 7.4.5 does not properly handle external URLs in movies, which allows remote attackers to obtain sensitive information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.4.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-04T17:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1015",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//Jul/msg00000.html",
          "name" : "APPLE-SA-2008-07-10",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29650",
          "name" : "29650",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31034",
          "name" : "31034",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019759",
          "name" : "1019759",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT1241",
          "name" : "http://support.apple.com/kb/HT1241",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28583",
          "name" : "28583",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-094A.html",
          "name" : "TA08-094A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1078",
          "name" : "ADV-2008-1078",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2064/references",
          "name" : "ADV-2008-2064",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41604",
          "name" : "quicktime-data-reference-bo(41604)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the data reference atom handling in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted movie."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.4.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-04T17:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1016",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29650",
          "name" : "29650",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://securitytracker.com/id?1019760",
          "name" : "1019760",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT1241",
          "name" : "http://support.apple.com/kb/HT1241",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28583",
          "name" : "28583",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-094A.html",
          "name" : "TA08-094A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1078",
          "name" : "ADV-2008-1078",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41605",
          "name" : "quicktime-movie-media-code-execution(41605)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Apple QuickTime before 7.4.5 does not properly handle movie media tracks, which allows remote attackers to execute arbitrary code via a crafted movie that triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.4.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-04T17:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1017",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//Jul/msg00000.html",
          "name" : "APPLE-SA-2008-07-10",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29650",
          "name" : "29650",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31034",
          "name" : "31034",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019761",
          "name" : "1019761",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT1241",
          "name" : "http://support.apple.com/kb/HT1241",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/490460/100/0/threaded",
          "name" : "20080403 ZDI-08-015: Apple QuickTime Clipping Region Heap Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28583",
          "name" : "28583",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-094A.html",
          "name" : "TA08-094A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1078",
          "name" : "ADV-2008-1078",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2064/references",
          "name" : "ADV-2008-2064",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-015",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-015",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41607",
          "name" : "quicktime-crgn-bo(41607)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in clipping region (aka crgn) atom handling in quicktime.qts in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted movie."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.4.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-04T17:44Z",
    "lastModifiedDate" : "2018-10-11T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1018",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//Jul/msg00000.html",
          "name" : "APPLE-SA-2008-07-10",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29650",
          "name" : "29650",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31034",
          "name" : "31034",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019762",
          "name" : "1019762",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT1241",
          "name" : "http://support.apple.com/kb/HT1241",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/490467/100/0/threaded",
          "name" : "20080403 ZDI-08-016: Apple QuickTime MP4A Atom Parsing Heap Corruption Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28583",
          "name" : "28583",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-094A.html",
          "name" : "TA08-094A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1078",
          "name" : "ADV-2008-1078",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2064/references",
          "name" : "ADV-2008-2064",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-016",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-016",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41606",
          "name" : "quicktime-chan-bo(41606)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via an MP4A movie with a malformed Channel Compositor (aka chan) atom."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.4.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-04T17:44Z",
    "lastModifiedDate" : "2018-10-11T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1019",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29650",
          "name" : "29650",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019763",
          "name" : "1019763",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT1241",
          "name" : "http://support.apple.com/kb/HT1241",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/490459/100/0/threaded",
          "name" : "20080403 ZDI-08-014: Apple Quicktime Multiple Opcode Memory Corruption Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28583",
          "name" : "28583",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-094A.html",
          "name" : "TA08-094A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1078",
          "name" : "ADV-2008-1078",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-014",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-014",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41609",
          "name" : "quicktime-pict-records-bo(41609)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in quickTime.qts in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted PICT image file, related to an improperly terminated memory copy loop."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.4.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-04T17:44Z",
    "lastModifiedDate" : "2018-10-11T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1020",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29650",
          "name" : "29650",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019764",
          "name" : "1019764",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT1241",
          "name" : "http://support.apple.com/kb/HT1241",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/490468/100/0/threaded",
          "name" : "20080403 ZDI-08-017: Apple QuickTime Kodak Encoding Heap Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28583",
          "name" : "28583",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-094A.html",
          "name" : "TA08-094A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1078",
          "name" : "ADV-2008-1078",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-017",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-017",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41610",
          "name" : "quicktime-pictimage-bo(41610)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in quickTime.qts in Apple QuickTime before 7.4.5 on Windows allows remote attackers to execute arbitrary code via a crafted PICT image file with Kodak encoding, related to error checking and error messages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.4.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-04T17:44Z",
    "lastModifiedDate" : "2018-10-11T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1021",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29650",
          "name" : "29650",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019765",
          "name" : "1019765",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT1241",
          "name" : "http://support.apple.com/kb/HT1241",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/490462/100/0/threaded",
          "name" : "20080403 ZDI-08-018: Apple QuickTime Run Length Encoding Heap Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28583",
          "name" : "28583",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-094A.html",
          "name" : "TA08-094A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1078",
          "name" : "ADV-2008-1078",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-018",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-018",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41612",
          "name" : "quicktime-animation-codec-bo(41612)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Animation codec content handling in Apple QuickTime before 7.4.5 on Windows allows remote attackers to execute arbitrary code via a crafted movie with run length encoding."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.4.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-04T17:44Z",
    "lastModifiedDate" : "2018-10-11T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1022",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29650",
          "name" : "29650",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019766",
          "name" : "1019766",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT1241",
          "name" : "http://support.apple.com/kb/HT1241",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/490461/100/0/threaded",
          "name" : "20080403 ZDI-08-019: Apple QuickTime Malformed VR obji Atom Parsing Memory Corruption Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28583",
          "name" : "28583",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-094A.html",
          "name" : "TA08-094A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1078",
          "name" : "ADV-2008-1078",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-019",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-019",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41613",
          "name" : "quicktime-obji-atoms-bo(41613)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted VR movie with an obji atom of zero size."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.4.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-04T17:44Z",
    "lastModifiedDate" : "2018-10-11T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1023",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29650",
          "name" : "29650",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019767",
          "name" : "1019767",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT1241",
          "name" : "http://support.apple.com/kb/HT1241",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28583",
          "name" : "28583",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-094A.html",
          "name" : "TA08-094A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1078",
          "name" : "ADV-2008-1078",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41615",
          "name" : "quicktime-clip-opcodes-bo(41615)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Clip opcode parsing in Apple QuickTime before 7.4.5 on Windows allows remote attackers to execute arbitrary code via a crafted PICT image file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.4.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-04T17:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1024",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Apr/msg00001.html",
          "name" : "APPLE-SA-2008-04-16",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT1467",
          "name" : "http://support.apple.com/kb/HT1467",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/529441",
          "name" : "VU#529441",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28813",
          "name" : "28813",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019868",
          "name" : "1019868",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0979/references",
          "name" : "ADV-2008-0979",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41864",
          "name" : "apple-safari-filedownload-code-execution(41864)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Apple Safari before 3.1.1, when running on Windows XP or Vista, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file download with a crafted file name, which triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:3.1:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-17T19:05Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1025",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "webkit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html",
          "name" : "APPLE-SA-2008-07-11",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Apr/msg00001.html",
          "name" : "APPLE-SA-2008-04-16",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29846",
          "name" : "29846",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31074",
          "name" : "31074",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT1467",
          "name" : "http://support.apple.com/kb/HT1467",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/705529",
          "name" : "VU#705529",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28814",
          "name" : "28814",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019869",
          "name" : "1019869",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1250/references",
          "name" : "ADV-2008-1250",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2094/references",
          "name" : "ADV-2008-2094",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41862",
          "name" : "apple-safari-webkit-hostname-xss(41862)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a colon in the hostname portion."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:webkit:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-17T19:05Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1026",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html",
          "name" : "APPLE-SA-2008-07-11",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Apr/msg00001.html",
          "name" : "APPLE-SA-2008-04-16",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29846",
          "name" : "29846",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31074",
          "name" : "31074",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3815",
          "name" : "3815",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT1467",
          "name" : "http://support.apple.com/kb/HT1467",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/490990/100/0/threaded",
          "name" : "20080416 ZDI-08-022: Apple Safari WebKit PCRE Handling Integer Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28815",
          "name" : "28815",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019870",
          "name" : "1019870",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1250/references",
          "name" : "ADV-2008-1250",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2094/references",
          "name" : "ADV-2008-2094",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-022",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-022",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/41859",
          "name" : "apple-safari-webkit-pcrecompile-bo(41859)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in the PCRE regular expression compiler (JavaScriptCore/pcre/pcre_compile.cpp) in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to execute arbitrary code via a regular expression with large, nested repetition counts, which triggers a heap-based buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:3.1:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-17T19:05Z",
    "lastModifiedDate" : "2018-10-11T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1027",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//May/msg00001.html",
          "name" : "APPLE-SA-2008-05-28",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30430",
          "name" : "30430",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1020130",
          "name" : "1020130",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29412",
          "name" : "29412",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29490",
          "name" : "29490",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-150A.html",
          "name" : "TA08-150A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1697",
          "name" : "ADV-2008-1697",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42703",
          "name" : "macosx-afpserver-security-bypass(42703)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Apple Filing Protocol (AFP) Server in Apple Mac OS X before 10.5.3 does not verify that requested files and directories are inside shared folders, which allows remote attackers to read arbitrary files via unspecified AFP traffic."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-06-02T21:30Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1028",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          }, {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//May/msg00001.html",
          "name" : "APPLE-SA-2008-05-28",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30430",
          "name" : "30430",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1020131",
          "name" : "1020131",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29412",
          "name" : "29412",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29487",
          "name" : "29487",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-150A.html",
          "name" : "TA08-150A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1697",
          "name" : "ADV-2008-1697",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42705",
          "name" : "macosx-appkit-code-execution(42705)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document file, as demonstrated by opening the document with TextEdit."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-06-02T21:30Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1030",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//May/msg00001.html",
          "name" : "APPLE-SA-2008-05-28",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30430",
          "name" : "30430",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1020135",
          "name" : "1020135",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29412",
          "name" : "29412",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29491",
          "name" : "29491",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-150A.html",
          "name" : "TA08-150A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1697",
          "name" : "ADV-2008-1697",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42709",
          "name" : "macosx-corefoundation-cfdatareplacebytes-bo(42709)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent attackers to execute arbitrary code or cause a denial of service (crash) via an invalid length argument, which triggers a heap-based buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-06-02T21:30Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1031",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//May/msg00001.html",
          "name" : "APPLE-SA-2008-05-28",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30430",
          "name" : "30430",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1020136",
          "name" : "1020136",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29412",
          "name" : "29412",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29480",
          "name" : "29480",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-150A.html",
          "name" : "TA08-150A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1697",
          "name" : "ADV-2008-1697",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42710",
          "name" : "macosx-coregraphics-unspec-code-execution(42710)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CoreGraphics in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document, related to an uninitialized variable."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-06-02T21:30Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1032",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//May/msg00001.html",
          "name" : "APPLE-SA-2008-05-28",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/30430",
          "name" : "30430",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1020137",
          "name" : "1020137",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29412",
          "name" : "29412",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29481",
          "name" : "29481",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-150A.html",
          "name" : "TA08-150A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1697",
          "name" : "ADV-2008-1697",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42711",
          "name" : "macosx-coretypes-weak-security(42711)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via an (1) Automator, (2) Help, (3) Safari, or (4) Terminal content type for a downloadable object, which does not trigger a \"potentially unsafe\" warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine feature in Mac OS X 10.5."
        }, {
          "lang" : "en",
          "value" : "Per: http://cwe.mitre.org/data/definitions/184.html\r\n'CWE-184: Incomplete Blacklist'"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-06-02T21:30Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1033",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "cups",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//May/msg00001.html",
          "name" : "APPLE-SA-2008-05-28",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30430",
          "name" : "30430",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1020145",
          "name" : "1020145",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29412",
          "name" : "29412",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29484",
          "name" : "29484",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-150A.html",
          "name" : "TA08-150A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1697",
          "name" : "ADV-2008-1697",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42713",
          "name" : "macosx-cups-info-disclosure(42713)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading the log data, related to \"authentication environment variables.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:cups:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-06-02T21:30Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1034",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//May/msg00001.html",
          "name" : "APPLE-SA-2008-05-28",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30430",
          "name" : "30430",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1020138",
          "name" : "1020138",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/566875",
          "name" : "VU#566875",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29412",
          "name" : "29412",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29483",
          "name" : "29483",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-150A.html",
          "name" : "TA08-150A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1697",
          "name" : "ADV-2008-1697",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42716",
          "name" : "macosx-helpviewer-bo(42716)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer underflow in Help Viewer in Apple Mac OS X before 10.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted help:topic URL that triggers a buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "10.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-06-02T21:30Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1035",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "ical",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//May/msg00001.html",
          "name" : "APPLE-SA-2008-05-28",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30430",
          "name" : "30430",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.coresecurity.com/?action=item&id=2219",
          "name" : "http://www.coresecurity.com/?action=item&id=2219",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/492414/100/0/threaded",
          "name" : "20080521 CORE-2008-0126: Multiple vulnerabilities in iCal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/492638/100/100/threaded",
          "name" : "20080527 Re: CORE-2008-0126: Multiple vulnerabilities in iCal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/492682/100/0/threaded",
          "name" : "20080528 Re: CORE-2008-0126: Multiple vulnerabilities in iCal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28633",
          "name" : "28633",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29412",
          "name" : "29412",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29486",
          "name" : "29486",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020095",
          "name" : "1020095",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-150A.html",
          "name" : "TA08-150A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1601",
          "name" : "ADV-2008-1601",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1697",
          "name" : "ADV-2008-1697",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Use-after-free vulnerability in Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to trigger memory corruption or possibly execute arbitrary code via an \"ATTACH;VALUE=URI:S=osumi\" line in a .ics file, which triggers a \"resource liberation\" bug.  NOTE: CVE-2008-2007 was originally used for this issue, but this is the appropriate identifier."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:ical:3.0.1:*:os_x:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-06-03T20:32Z",
    "lastModifiedDate" : "2018-10-11T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1036",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2008//May/msg00001.html",
          "name" : "APPLE-SA-2008-05-28",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30430",
          "name" : "30430",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/34290",
          "name" : "34290",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/34777",
          "name" : "34777",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1020139",
          "name" : "1020139",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0064",
          "name" : "http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0064",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2009/dsa-1762",
          "name" : "DSA-1762",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2009-0296.html",
          "name" : "RHSA-2009:0296",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29412",
          "name" : "29412",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29488",
          "name" : "29488",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-747-1",
          "name" : "USN-747-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-150A.html",
          "name" : "TA08-150A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1697",
          "name" : "ADV-2008-1697",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42717",
          "name" : "macosx-icu-security-bypass(42717)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10824",
          "name" : "oval:org.mitre.oval:def:10824",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Enterprise Linux 5, and other operating systems omits some invalid character sequences during conversion of some character encodings, which might allow remote attackers to conduct cross-site scripting (XSS) attacks."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-06-02T21:30Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1037",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "packeteer",
            "product" : {
              "product_data" : [ {
                "product_name" : "packetshaper",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.2.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "policycenter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29119",
          "name" : "29119",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3701",
          "name" : "3701",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488712/100/0/threaded",
          "name" : "20080224 Packeteer Products File Listing XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27982",
          "name" : "27982",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019501",
          "name" : "1019501",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the file listing function in the web management interface in Packeteer PacketShaper and PolicyCenter 8.2.2 allows remote attackers to inject arbitrary web script or HTML via the FILELIST parameter to an arbitrary component, which triggers injection into an Error Report page."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:packeteer:packetshaper:8.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:packeteer:policycenter:8.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2018-10-11T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1038",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drbenhur.com",
            "product" : {
              "product_data" : [ {
                "product_name" : "dbhcms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29110",
          "name" : "29110",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27996",
          "name" : "27996",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40835",
          "name" : "dbhcms-modextmanager-file-include(40835)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5189",
          "name" : "5189",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in mod/mod.extmanager.php in DBHcms 1.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the extmanager_install parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drbenhur.com:dbhcms:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drbenhur.com:dbhcms:1.1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1039",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "porar",
            "product" : {
              "product_data" : [ {
                "product_name" : "webboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29102",
          "name" : "29102",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27989",
          "name" : "27989",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40839",
          "name" : "porar-question-sql-injection(40839)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5185",
          "name" : "5185",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in question.asp in PORAR WEBBOARD allows remote attackers to execute arbitrary SQL commands via the QID parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:porar:webboard:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1040",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fujitsu",
            "product" : {
              "product_data" : [ {
                "product_name" : "interstage_application_server_enterprise",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v9.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v9.0.0a",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "interstage_application_server_standard_j",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v9.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v9.0.0a",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "interstage_apworks_enterprise",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "interstage_apworks_standard_j",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "interstage_studio_enterprise",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v9.0.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "interstage_studio_standard_j",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v9.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29088",
          "name" : "29088",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.fujitsu.com/global/support/software/security/products-f/interstage-200804e.html",
          "name" : "http://www.fujitsu.com/global/support/software/security/products-f/interstage-200804e.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27966",
          "name" : "27966",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0662",
          "name" : "ADV-2008-0662",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the Single Sign-On function in Fujitsu Interstage Application Server 8.0.0 through 8.0.3 and 9.0.0, Interstage Studio 8.0.1 and 9.0.0, and Interstage Apworks 8.0.0 allows remote attackers to execute arbitrary code via a long URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:8.0.0:*:rehl_as4_x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:8.0.0:*:rhel_as4_em64t:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:8.0.0:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:8.0.0:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:8.0.1:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:8.0.2:*:rhel_as4_em64t:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:8.0.2:*:rhel_as4_x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:8.0.2:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:8.0.2:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:8.0.3:*:rhel_as4_em64t:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:8.0.3:*:rhel_as4_x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:8.0.3:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:8.0.3:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:v9.0.0:*:rhel5_intel64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:v9.0.0:*:rhel5_ipf:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:v9.0.0:*:rhel5_x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:v9.0.0:*:rhel_as4_em64t:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:v9.0.0:*:rhel_as4_ipf:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:v9.0.0:*:rhel_as4_x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:v9.0.0:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:v9.0.0:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:v9.0.0a:*:rhel5_ipf:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:v9.0.0a:*:rhel_as4_ipf:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_enterprise:v9.0.0a:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:8.0.0:*:rhel_as4_em64t:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:8.0.0:*:rhel_as4_x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:8.0.0:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:8.0.0:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:8.0.2:*:rhel_as4_em64t:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:8.0.2:*:rhel_as4_x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:8.0.2:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:8.0.2:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:8.0.3:*:rhel_as4_em64t:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:8.0.3:*:rhel_as4_x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:8.0.3:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:8.0.3:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:v9.0.0.0:*:rhel5_intel64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:v9.0.0.0:*:rhel5_ipf:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:v9.0.0.0:*:rhel5_x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:v9.0.0.0:*:rhel_as4_em64t:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:v9.0.0.0:*:rhel_as4_ipf:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:v9.0.0.0:*:rhel_as4_x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:v9.0.0.0:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:v9.0.0.0:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_application_server_standard_j:v9.0.0a:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_apworks_enterprise:8.0.0:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_apworks_standard_j:8.0.0:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_studio_enterprise:8.0.1:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_studio_enterprise:v9.0.0:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_studio_standard_j:8.0.1:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fujitsu:interstage_studio_standard_j:v9.0.0:*:windows:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2011-03-08T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1041",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "matts_whois",
            "product" : {
              "product_data" : [ {
                "product_name" : "matts_whois",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29093",
          "name" : "29093",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.packetstormsecurity.org/0802-exploits/mattswhois-xss.txt",
          "name" : "http://www.packetstormsecurity.org/0802-exploits/mattswhois-xss.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27974",
          "name" : "27974",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in mwhois.php in Matt Wilson Matt's Whois (MWhois) allows remote attackers to inject arbitrary web script or HTML via the domain parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matts_whois:matts_whois:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2008-09-05T21:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1042",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux_web_shop",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_download_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29089",
          "name" : "29089",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27961",
          "name" : "27961",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40795",
          "name" : "phpdownloadmanager-body-file-include(40795)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5183",
          "name" : "5183",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in include/body.inc.php in Linux Web Shop (LWS) php Download Manager 1.0 and 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:linux_web_shop:php_download_manager:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1043",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux_web_shop",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_user_base",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/494140/100/0/threaded",
          "name" : "20080710 phpuserbase 1.3 (menu) Remote File Inclusion Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27963",
          "name" : "27963",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40794",
          "name" : "phpuserbase-header-file-include(40794)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5180",
          "name" : "5180",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in templates/default/header.inc.php in Linux Web Shop (LWS) php User Base 1.3 BETA allows remote attackers to execute arbitrary PHP code via a URL in the menu parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:linux_web_shop:php_user_base:1.3:beta:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2018-10-11T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1044",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "move_networks_inc",
            "product" : {
              "product_data" : [ {
                "product_name" : "move_media_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "qunatum_streaming_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.7.4_39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.7.6.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060460.html",
          "name" : "20080226 Move Networks Quantum Streaming Player UploadLogs() Buffer Overflow",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29108",
          "name" : "29108",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27995",
          "name" : "27995",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0684",
          "name" : "ADV-2008-0684",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5190",
          "name" : "5190",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the Quantum Streaming Player (Quantum Streaming IE Player) ActiveX control (aka QSP2IE.QSP2IE) in qsp2ie07076007.dll 7.7.6.7 and qsp2ie07074039.dll 7.7.4.39 in Move Media Player allows remote attackers to execute arbitrary code via a long argument to the UploadLogs method, a different vector than CVE-2007-4722.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:move_networks_inc:move_media_player:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:move_networks_inc:qunatum_streaming_player:7.7.4_39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:move_networks_inc:qunatum_streaming_player:7.7.6.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1045",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "alkacon",
            "product" : {
              "product_data" : [ {
                "product_name" : "opencms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29121",
          "name" : "29121",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3702",
          "name" : "3702",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488708/100/0/threaded",
          "name" : "20080224 Alkacon OpenCms tree_files.jsp resource XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27986",
          "name" : "27986",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the file tree navigation function in system/workplace/views/explorer/tree_files.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the resource parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alkacon:opencms:7.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2018-10-11T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1046",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "quinsonnas",
            "product" : {
              "product_data" : [ {
                "product_name" : "quinsonnas_mail_checker",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.55",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://www.exploit-db.com/exploits/5176",
          "name" : "5176",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in footer.php in Quinsonnas Mail Checker 1.55 allows remote attackers to execute arbitrary PHP code via a URL in the op[footer_body] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:quinsonnas:quinsonnas_mail_checker:1.55:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1047",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tiki",
            "product" : {
              "product_data" : [ {
                "product_name" : "tikiwiki_cms/groupware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev.tikiwiki.org/tiki-view_tracker_item.php?itemId=1498",
          "name" : "http://dev.tikiwiki.org/tiki-view_tracker_item.php?itemId=1498",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29092",
          "name" : "29092",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://tikiwiki.org/ReleaseNotes1910",
          "name" : "http://tikiwiki.org/ReleaseNotes1910",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27968",
          "name" : "27968",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0661",
          "name" : "ADV-2008-0661",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in tiki-edit_article.php in TikiWiki before 1.9.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tiki:tikiwiki_cms\\/groupware:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2012-10-24T04:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1048",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "plume-cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "plume_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29116",
          "name" : "29116",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.digitrustgroup.com/advisories/web-application-security-plume-cms.html",
          "name" : "http://www.digitrustgroup.com/advisories/web-application-security-plume-cms.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27999",
          "name" : "27999",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019507",
          "name" : "1019507",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40841",
          "name" : "plume-xmedia-xss(40841)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in manager/xmedia.php in Plume CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the dir parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plume-cms:plume_cms:1.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1049",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "positive_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "h-sphere",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5_patch_10",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "3.0_patch_8",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "sitestudio",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29084",
          "name" : "29084",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.psoft.net/misc/hs_ss_technical_update.html",
          "name" : "http://www.psoft.net/misc/hs_ss_technical_update.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28002",
          "name" : "28002",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019506",
          "name" : "1019506",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40846",
          "name" : "hsphere-sitestudio-unspecified(40846)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Parallels SiteStudio before 1.7.2, and 1.8.x before 1.8b, as used in Parallels H-Sphere 3.0 before Patch 9 and 2.5 before Patch 11, has unknown impact and attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.5_patch_10"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0_patch_8"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:sitestudio:1.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:sitestudio:1.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1050",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "softbiz",
            "product" : {
              "product_data" : [ {
                "product_name" : "jokes_and_funny_pictures_script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3703",
          "name" : "3703",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488706/100/0/threaded",
          "name" : "20080224 Softbiz jokes and funny pictures (index.php) sql injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27973",
          "name" : "27973",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:softbiz:jokes_and_funny_pictures_script:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2018-10-11T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1051",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpprofiles",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpprofiles_",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27952",
          "name" : "27952",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5175",
          "name" : "5175",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in include/body_comm.inc.php in phpProfiles 4.5.2 BETA allows remote attackers to execute arbitrary PHP code via a URL in the content parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:phpprofiles:phpprofiles_:4.5.2:beta:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1052",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "netwin",
            "product" : {
              "product_data" : [ {
                "product_name" : "surgeftp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3a2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/surgeftpizza-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/surgeftpizza-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29096",
          "name" : "29096",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3704",
          "name" : "3704",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488745/100/0/threaded",
          "name" : "20080225 NULL pointer in SurgeFTP 2.3a2",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27993",
          "name" : "27993",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40843",
          "name" : "surgeftp-contentlength-dos(40843)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL pointer dereference when memory allocation fails."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgeftp:2.3a2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2018-10-11T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1053",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpnuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "kose_yazilari_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/27991",
          "name" : "27991",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40848",
          "name" : "koseyazilari-artid-sql-injection(40848)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5186",
          "name" : "5186",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the artid parameter in a (1) viewarticle or (2) printpage action to modules.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpnuke:kose_yazilari_module:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2017-09-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1054",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "netwin",
            "product" : {
              "product_data" : [ {
                "product_name" : "surgemail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8b3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8g3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9b2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0g2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1c7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2a6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2c9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2c10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2g2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2g3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0c2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1s",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8f3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8i2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8i3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38k",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38k4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/surgemailz-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/surgemailz-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/29105",
          "name" : "29105",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/3705",
          "name" : "3705",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488741/100/0/threaded",
          "name" : "20080225 Format string and buffer-overflow in SurgeMail 38k4",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27992",
          "name" : "27992",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019500",
          "name" : "1019500",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0678",
          "name" : "ADV-2008-0678",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40834",
          "name" : "surgemail-webmail-bo(40834)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and beta 39a, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via an HTTP request with multiple long headers to webmail.exe and unspecified other CGI executables, which triggers an overflow when assigning values to environment variables.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:1.8a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:1.8b3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:1.8d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:1.8e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:1.8g3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:1.9b2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.0c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.0e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.0g2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.1c7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.2a6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.2c9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.2c10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.2g2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.2g3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:3.0a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:3.0c2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:3.1s:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:3.8f3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:3.8i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:3.8i2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:3.8i3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:38k:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:38k4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2018-10-11T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1055",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "netwin",
            "product" : {
              "product_data" : [ {
                "product_name" : "surgemail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8b3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8g3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9b2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0g2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1c7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2a6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2c9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2c10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2g2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2g3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0c2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8f3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38k4",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "39a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "beta_39a",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "webmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1s",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/surgemailz-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/surgemailz-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29105",
          "name" : "29105",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29137",
          "name" : "29137",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/3705",
          "name" : "3705",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/488741/100/0/threaded",
          "name" : "20080225 Format string and buffer-overflow in SurgeMail 38k4",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27990",
          "name" : "27990",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019500",
          "name" : "1019500",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0678",
          "name" : "ADV-2008-0678",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40833",
          "name" : "surgemail-webmail-format-string(40833)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in the page parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:1.8a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:1.8b3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:1.8d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:1.8e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:1.8g3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:1.9b2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.0c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.0e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.0g2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.1c7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.2a6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.2c9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.2c10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.2g2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:2.2g3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:3.0a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:3.0c2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:3.8f3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "38k4"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:39a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:surgemail:beta_39a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netwin:webmail:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.1s"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-27T19:44Z",
    "lastModifiedDate" : "2018-10-11T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1056",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symark",
            "product" : {
              "product_data" : [ {
                "product_name" : "powerbroker",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.01",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29111",
          "name" : "29111",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.mnin.org/advisories/2008_symarkpb.pdf",
          "name" : "http://www.mnin.org/advisories/2008_symarkpb.pdf",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28015",
          "name" : "28015",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.symark.com/support/PBFeb2008Announcement.html",
          "name" : "http://www.symark.com/support/PBFeb2008Announcement.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40872",
          "name" : "powerbroker-argv-bo(40872)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in Symark PowerBroker 2.8 through 5.0.1 allow local users to gain privileges via a long argv[0] string when executing (1) pbrun, (2) pbsh, or (3) pbksh.  NOTE: the product is often installed in environments with trust relationships that facilitate subsequent remote compromises."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symark:powerbroker:2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symark:powerbroker:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symark:powerbroker:3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symark:powerbroker:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symark:powerbroker:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symark:powerbroker:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symark:powerbroker:5.01:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-28T19:44Z",
    "lastModifiedDate" : "2017-08-08T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1057",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openbsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "openbsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29078",
          "name" : "29078",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.openbsd.org/errata42.html#008_ip6rthdr",
          "name" : "20080225 008: RELIABILITY FIX: February 25, 2008",
          "refsource" : "OPENBSD",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27965",
          "name" : "27965",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019496",
          "name" : "1019496",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0660",
          "name" : "ADV-2008-0660",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ip6_check_rh0hdr function in netinet6/ip6_input.c in OpenBSD 4.2 allows attackers to cause a denial of service (panic) via malformed IPv6 routing headers."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:openbsd:openbsd:4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-28T19:44Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2008-1058",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openbsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "openbsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/29078",
          "name" : "29078",
          "refsource" : "S